July 28, 2026 12 min

AI Act for websites and online stores — what owners must know

The AI Act does not mean every store using an AI product-description generator needs certification. The most attention should go to chatbots, synthetic content, recruitment, credit scoring and customer data processing. Here is what to review before 2 August 2026.

AI Act for websites and online stores — what owners must know

The AI Act does not automatically impose sweeping obligations on every company that uses ChatGPT, an image generator or a product-recommendation tool. For most website and store owners the most important duties will relate to chatbot transparency, control over AI-generated content and the lawful use of customer data.

Heavier requirements can appear when an AI system is used for recruitment, credit scoring, emotion recognition, biometric categorisation or decisions that significantly affect a specific person.

Does the AI Act apply to an ordinary online store?

Yes, but the scope of obligations depends on how the store uses AI. Typical uses — spam filtering, help with product descriptions, or simple recommendations of similar items — most often fall under minimal or limited risk.

The European Commission points out that the vast majority of AI systems used in the Union fall into the minimal- or zero-risk category, for which the AI Act does not set up an extensive certification regime. That does not mean such tools can be deployed without any oversight. The following may still apply:

  • GDPR,
  • consumer law,
  • copyright,
  • advertising rules,
  • rules on prices and promotions,
  • the licence terms of the tool provider.

The AI Act is therefore one of several regulatory layers that has to be taken into account.

First, determine the company''s role: provider or deployer?

This is one of the most important steps of the analysis.

Deployer of an AI system

Most store owners will be a deployer — an organisation that uses an AI system in the course of its own activity.

Example: a store installs a ready-made chatbot supplied by a third party and uses it to answer customer questions.

Provider of an AI system

A company can become a provider when it:

  • develops the system itself,
  • commissions its development,
  • makes it available under its own name or brand,
  • sells or deploys it as its own product.

Example: an agency builds a shopping assistant for clients under its own brand name. Even if it uses another vendor''s model under the hood, it may have additional duties as a system provider.

Key dates for website and store owners

The AI Act applies in stages. The timeline reflects changes introduced by the AI Omnibus.

  1. 1 sierpnia 2024
    AI Act enters into force

    Start of the two-year transition period for most obligations.

  2. 2 lutego 2025
    Prohibitions apply

    Bans on unacceptable AI uses enter into force.

  3. 2 sierpnia 2025
    Rules for general-purpose models

    Obligations for GPAI model providers (documentation, transparency).

  4. 27 lipca 2026
    AI Omnibus

    Amends part of the AI Act timeline and obligations.

  5. 2 sierpnia 2026
    Transparency (Art. 50)

    Chatbots and selected synthetic content must be clearly labelled.

  6. 2 grudnia 2027
    High-risk systems

    Selected obligations for employment and biometrics.

  7. 2 sierpnia 2028
    High risk in regulated products

    Requirements for systems embedded in harmonised products.

How does the AI Act affect the most common AI uses in e-commerce?

Use caseTypical AI Act relevanceWhat the owner should do
Customer-support chatbotInteraction transparency dutiesClearly inform the customer they are talking to AI, and check the provider configuration
Product-description generatorUsually minimal riskIntroduce fact, spec, advertising and copyright checks
Generated product photosPossible duties around deepfakes / misleading contentAssess whether the visual suggests untrue product features
Product recommendationsUsually minimal riskReview profiling, personal data and how the recommendation is explained
Price personalisationNot necessarily a high-risk systemMeet consumer-law information duties and GDPR
Automated candidate screeningMay be a high-risk systemVerify classification, documentation, human oversight and the provider
Credit scoringMay be a high-risk systemEstablish who actually makes the decision and who is the deployer
Emotion recognition / biometricsElevated legal riskDo not deploy without dedicated legal and technical analysis
Own chatbot sold to clientsThe company may become a providerAnalyse the full provider obligations, not only those of a user

A chatbot on the site: do you have to inform the customer they are talking to AI?

From 2 August 2026, systems designed to interact directly with humans must be designed so that the user is informed they are talking to AI — unless this is obvious to a reasonably well-informed person.

The information must be clear and given no later than at the first interaction. The Commission cites chatbots, AI agents and digital avatars as typical examples of systems covered by this rule. A compliant message may read:

You are chatting with an assistant powered by artificial intelligence. Answers may contain errors. You can ask to speak to a human at any time.

The formal obligation to design the system appropriately sits primarily with its provider. A store owner should nonetheless not assume that an off-the-shelf plugin automatically meets every requirement.

  • The AI notice is visible before the first reply
  • It is not hidden by your own site template
  • The user can request a human at any time
  • You know what data the chatbot provider receives
  • You know whether and for how long conversations are stored
  • Conversations are not used to train models without a legal basis
  • The system handles complaints, returns and warranty questions correctly

Placing information about AI only in the terms of service or privacy policy may be insufficient if the user does not see it during the interaction.

Does every AI-generated piece of text need a label?

No. The AI Act does not impose a general duty to add a "generated by AI" label to every product description, blog article or marketing message. Specific obligations concern, among others:

  • deepfake content,
  • texts published to inform the public on matters of public interest,
  • synthetic content that the system provider should mark in a machine-readable way.

For text about matters of public interest, the disclosure duty may not apply where the material has been through human or editorial review and a person or company takes editorial responsibility for the publication. A product description in a store is generally not a publication about a matter of public interest — nonetheless the company is responsible for its accuracy.

If a generator invents a feature the device does not have, a wrong ingredient list or a fake certification, the information may mislead the customer regardless of whether the text was written by a human or a language model.

AI-generated photos and virtual models

Particular care is needed with:

  • images presenting the product in a way that cannot be achieved in reality,
  • generated recommendations from a supposed expert,
  • material imitating a specific person''s statement,
  • synthetic customer recordings,
  • artificially generated "before and after" photos.

If the material meets the definition of a deepfake, an entity using it professionally may be required to inform the audience about its artificial origin or manipulation. Providers of generative AI systems in turn have duties around machine-readable labelling of synthetic content. Transparency rules start to apply on 2 August 2026.

Even where the AI Act does not clearly require a label in a specific case, it is worth adding a note: "The visual has been computer-generated. The product may look different from the visualisation."

Product recommendations and personalisation

Recommending products automatically based on browsing history is generally not, in itself, a high-risk system under the AI Act. You still need to check:

  • what data is used,
  • whether the customer is profiled,
  • whether data is transferred outside the European Economic Area,
  • whether the recommendation affects only the order of products or also their prices,
  • whether the user can object to marketing profiling,
  • whether the system does not discriminate against certain groups of customers.

Using personal data in AI models and systems remains subject to GDPR. The European Data Protection Board stresses that compliance has to be assessed case by case — taking into account the legal basis, the necessity of processing and the reasonable expectations of the data subjects.

How does the AI Act regulate dynamic prices?

Simply using dynamic prices does not automatically make the system high-risk under the AI Act. You do need to distinguish between:

  • price changes driven by demand, availability or time,
  • individual pricing based on the profile of a specific customer.

Consumer law requires informing the customer when the price has been personalised based on automated decision-making. This duty does not apply to ordinary price changes driven by market conditions. A store should therefore not limit its analysis to the AI Act alone — a pricing mechanism may need a combined assessment against consumer law and GDPR.

When can AI used by a store be a high-risk system?

The most significant uses are those going beyond ordinary product sales.

Recruitment

AI systems used to analyse CVs, score candidates, automatically reject applications, run scored video interviews and monitor and evaluate employees may be classified as high-risk.

The corresponding rules are due to apply from 2 December 2027. A store owner should ask the recruitment-system provider:

  • how the system is classified,
  • whether a decision can be verified by a human,
  • what data is analysed,
  • whether the system produces a candidate score,
  • how long results and logs are retained,
  • how errors and discrimination are detected.

Credit scoring

If the store itself uses AI to assess a consumer''s creditworthiness or set their credit score, the use case may fall into the high-risk category. A common situation: the customer chooses instalments and the decision is taken by the bank or an independent payment operator — in that model you need to establish who actually controls the system and takes the decision.

Simply placing a "buy in instalments" button on the site does not automatically make the store a deployer of a credit-scoring system.

Emotion recognition and biometrics

Analysing a customer''s face through a camera, inferring their mood or categorising users based on biometric traits comes with significant legal risk. Such a solution should not be deployed on the sole strength of a vendor stating that "the system complies with the AI Act". A separate analysis of the purpose, legal basis, data categories, proportionality and any prohibitions is required.

Which practices are prohibited?

The AI Act bans selected uses considered unacceptable. For a store owner, the ban on deliberately manipulative or deceptive techniques that materially impair a person''s ability to make an informed decision and cause or may cause significant harm is particularly relevant.

Do employees still have to be trained on AI?

Yes. The original AI Act text imposes a general duty to ensure an adequate level of AI literacy among staff. This duty started to apply on 2 February 2025 and covers every company — including a store — that uses AI in its operations.

Personal data and GDPR in an AI context

If conversations with a chatbot, form fields or training data include:

  • name, address, phone, email,
  • order history,
  • financial data,
  • data on health or allergies,

personal-data processing is taking place. The company should check, among other things: the legal basis for processing, the scope of information in the privacy policy, the tool provider''s role, the data-processing agreement, data location, retention of conversations, whether conversations may be used to train models, and whether a data-protection impact assessment (DPIA) is required.

Example: a store with 4 different AI uses

Imagine a store that at the same time uses:

  • a chatbot answering customer questions,
  • a product-description generator,
  • a recommendation system,
  • a plugin scoring candidate CVs.

In that case the owner should carry out four separate analyses.

Chatbot

Deploy the AI-interaction notice, review how conversations are processed and provide a way to reach a human.

Description generator

Introduce mandatory checks of parameters, safety instructions, prices, certifications and stock information.

Recommendations

Determine whether the system uses personal data, profiling or information from external ad networks.

Recruitment

Ask the provider about the system classification and human oversight — from 2 December 2027 high-risk-system requirements may apply.

A 6-step checklist for store owners

  • Inventory every place where the store uses AI (chatbot, generators, recommendations, recruitment, prices)
  • For each use case set the risk under the AI Act (minimal / limited / high / prohibited)
  • Determine your role — are you only a deployer, or do you offer the solution under your own brand (provider)
  • Check the inputs — is customer, employee, candidate or confidential data reaching the system
  • Vet the provider: system description, data-use terms, sub-processors, processing location, transparency features, incident-reporting procedure
  • Implement AI-interaction notices and train the team (Art. 4 AI-literacy duty)

Penalties and real-world impact

Maximum penalty levels depend on the type of breach. For prohibited practices they can reach up to EUR 35 million or 7% of total global annual turnover. For other breaches the maximum can be up to EUR 15 million or 3% of turnover. For SMEs the lower of the applicable thresholds applies.

That does not mean a missing chatbot notice will automatically lead to a maximum-level fine — the assessment takes into account the nature, gravity and duration of the breach. High penalties should not, however, distract from the more likely consequences of a badly deployed system:

  • customer complaints,
  • wrong orders,
  • data loss,
  • GDPR breaches,
  • loss of trust and reputation.

What next?

Do you use a chatbot, a content generator, automated recommendations or AI tools connected to WooCommerce, PrestaShop or a CRM? An implementation audit should cover not only the plugin itself but also the data flow, site configuration, user-facing messaging, contracts with providers and the answer-review procedure.

Book an AI audit of your website or online store →

Najczęściej zadawane pytania

  • The AI Act can apply to any store using AI systems, but the scope of obligations depends on how they are used. A simple content generator usually does not trigger the same duties as a system scoring candidates or credit.

Gotowy, żeby przyspieszyć rozwój swojej firmy?

Umów bezpłatną konsultację — 30 minut konkretnych rekomendacji dla Twojego biznesu.