AI Act · E-commerce

AI Act for E-commerce: Recommendations, Chatbots and Compliance

Recommendation engines and dynamic pricing in e-commerce are generally not high-risk. Learn the Art. 50 transparency obligations, the Art. 5 manipulation prohibition and AEPD fines.

Is your e-commerce AI high-risk under the AI Act?

The AI Act (Regulation (EU) 2024/1689) generally does not classify recommendation engines and dynamic pricing in e-commerce as high-risk. However, there are exceptions and obligations to comply with:

When e-commerce AI is high-risk:

  • If used for credit scoring / creditworthiness assessment (Annex III point 5(b)) — e.g. purchase financing
  • If used for life and health insurance pricing (Annex III point 5(c))
  • If used for recruitment or worker management (Annex III point 4)
  • If it deploys prohibited practices under Art. 5

Chatbots and conversation: Art. 50(1) requires informing users that they are interacting with an AI system, unless it is obvious. Art. 50(2)-(4) may require disclosure of synthetically generated content (product images, reviews, AI-generated influencers).

Manipulation prohibition: Art. 5(1)(a) prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort behaviour. An e-commerce using AI dark patterns to manipulate purchase decisions may fall under this prohibition.

Emotion recognition and biometric categorisation: If used for customer analysis, it may be high-risk (Annex III point 1) or prohibited, depending on the context.

  • Recommendation engine classification — We determine whether your AI is high-risk under Annex III
  • Art. 50 compliance — We implement transparency obligations for chatbots and synthetic content
  • Dark patterns audit — We verify your AI does not engage in prohibited manipulation (Art. 5(1)(a))
  • LSSI coordination — We integrate AI Act and LSSI (Law 34/2002) for cookies and e-commerce
  • Technical documentation — We prepare Art. 11 documentation for high-risk e-commerce AI

AI Act obligations for E-commerce

AI Act obligations for e-commerce depend on the AI classification:

Limited-risk AI (chatbots, synthetic content):

  • Inform users they are interacting with AI (Art. 50(1))
  • Mark AI-generated synthetic content (Art. 50(2)-(4))
  • These obligations enter into force on 2 August 2026

High-risk AI (credit scoring, insurance):

  • Risk management system (Art. 9)
  • Training data quality (Art. 10)
  • Technical documentation and record-keeping (Art. 11)
  • Transparency for deployers (Art. 13)
  • Human oversight (Art. 14)
  • Accuracy, robustness and cybersecurity (Art. 15)
  • Conformity assessment (Art. 6 + Annex III)
  • EU database registration (Art. 49)

Prohibited practices (Art. 5):

  • Subliminal manipulation (Art. 5(1)(a)) — in force since 2 February 2025
  • Exploitation of vulnerabilities (Art. 5(1)(b))
  • Social scoring (Art. 5(1)(c))

Minimal-risk AI:

  • No specific obligations
  • Voluntary codes of conduct

Timeline: Art. 50 transparency obligations enter into force on 2 August 2026. Prohibited practices under Art. 5 have been in force since 2 February 2025. High-risk systems under Annex III must comply before 2 December 2027.

AI use cases in E-commerce and their classification

Use caseAI Act classificationApplicable rule
Product recommendation engineMinimal (generally)GDPR + LSSI
Dynamic pricingMinimal (generally)GDPR + LSSI
Customer service chatbotLimited riskArt. 50(1) transparency
Synthetic content generation (reviews, images)Limited riskArt. 50(2)-(4) marking
Credit scoring for financingHigh riskAnnex III, point 5(b)
Insurance pricingHigh riskAnnex III, point 5(c)
AI dark patternsProhibitedArt. 5(1)(a)
Customer emotion recognitionHigh-risk (if not prohibited)Annex III point 1(c) + GDPR Art. 9

Real enforcement cases in e-commerce

  • AEPD — SEAT, €12,000 (2024) — Non-technical cookies without consent and no consent withdrawal (PS/00284/2024). Source: Confilegal
  • AEPD — Guide on the use of cookies: AEPD
  • AEPD — Guide to safe online shopping: AEPD
  • AEPD — Decalogue for privacy policies: AEPD
  • EDPB — Guidelines 8/2020 on social media targeting: EDPB
  • EDPB — Cookie Banner Taskforce Report (2023): EDPB

AI Act compliance checklist for E-commerce

  • Identify all AI uses in the e-commerce
  • Classify each use under Annex III
  • Verify no prohibited dark patterns (Art. 5(1)(a))
  • Implement chatbot transparency (Art. 50(1))
  • Mark AI-generated synthetic content (Art. 50(2)-(4))
  • If high-risk: risk management system (Art. 9)
  • If high-risk: technical documentation (Art. 11)
  • If high-risk: conformity assessment and EU database registration
  • Coordinate with GDPR: legal bases, data subject rights, Art. 22
  • Coordinate with LSSI: cookie consent, consumer information
  • Verify free and specific consent for non-technical cookies
  • Implement right to object to profiling (Art. 21 GDPR)

Official sources


This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.

Featured Services

Frequently Asked Questions

Are recommendation engines high-risk under the AI Act?

Generally no. Recommendation engines and dynamic pricing in e-commerce are not classified as high-risk under Annex III, unless used for credit scoring (5b), life and health insurance (5c), recruitment (4) or they deploy prohibited practices under Art. 5. However, they must comply with the general obligations of the AI Act, the GDPR and the LSSI.

What obligations does an e-commerce chatbot have?

Art. 50(1) of the AI Act requires informing users that they are interacting with an AI system, unless it is obvious. If the chatbot generates synthetic content (generated responses, product images), Art. 50(2)-(4) may require it to be marked as artificially generated. These obligations enter into force on 2 August 2026.

Are AI dark patterns prohibited?

Yes. Art. 5(1)(a) of the AI Act prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort a person's behaviour in a way that causes or is likely to cause significant harm. An e-commerce using AI to design dark patterns that manipulate purchase decisions may fall under this prohibition, in force since 2 February 2025.

What fines does the AI Act provide for e-commerce?

Maximum fines are: up to €35 million or 7% of global turnover for prohibited practices (including dark patterns); up to €15 million or 3% for breach of high-risk obligations; up to €7.5 million or 1.5% for incorrect information to authorities. For SMEs and startups, the lower absolute amount applies.

How does the AI Act relate to the LSSI in e-commerce?

The AI Act regulates AI systems, while the LSSI (Law 34/2002) regulates information society services and e-commerce, including cookies and consent. Both regulations apply simultaneously. An e-commerce using AI to personalise content must comply with the AI Act (transparency, no manipulation) and the LSSI (cookie consent, consumer information).

What enforcement cases exist in e-commerce?

The AEPD fined SEAT €20,000 (reduced to €12,000) in 2024 for deploying non-technical cookies without consent and not allowing consent withdrawal (PS/00284/2024). Although not specifically an AI case, it illustrates the AEPD's active supervision in the e-commerce sector and the importance of LSSI compliance.

When is emotion recognition high-risk in e-commerce?

Emotion recognition is classified as high-risk under Annex III point 1(c) where not prohibited. Art. 5(1)(f) prohibits emotion recognition in the workplace and educational institutions, but not in e-commerce. However, using emotion recognition for customer analysis in e-commerce may be high-risk and requires conformity assessment, in addition to GDPR compliance (biometric data, Art. 9).

Which authorities supervise the AI Act in e-commerce in Spain?

The AESIA supervises the AI Act. The AEPD supervises personal data processing under the GDPR and the LSSI. In AI e-commerce cases, both authorities may intervene. The AEPD has published guides on cookies, safe online shopping and privacy policies.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us