Is your e-commerce AI high-risk under the AI Act?
The AI Act (Regulation (EU) 2024/1689) generally does not classify recommendation engines and dynamic pricing in e-commerce as high-risk. However, there are exceptions and obligations to comply with:
When e-commerce AI is high-risk:
- If used for credit scoring / creditworthiness assessment (Annex III point 5(b)) — e.g. purchase financing
- If used for life and health insurance pricing (Annex III point 5(c))
- If used for recruitment or worker management (Annex III point 4)
- If it deploys prohibited practices under Art. 5
Chatbots and conversation: Art. 50(1) requires informing users that they are interacting with an AI system, unless it is obvious. Art. 50(2)-(4) may require disclosure of synthetically generated content (product images, reviews, AI-generated influencers).
Manipulation prohibition: Art. 5(1)(a) prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort behaviour. An e-commerce using AI dark patterns to manipulate purchase decisions may fall under this prohibition.
Emotion recognition and biometric categorisation: If used for customer analysis, it may be high-risk (Annex III point 1) or prohibited, depending on the context.
- Recommendation engine classification — We determine whether your AI is high-risk under Annex III
- Art. 50 compliance — We implement transparency obligations for chatbots and synthetic content
- Dark patterns audit — We verify your AI does not engage in prohibited manipulation (Art. 5(1)(a))
- LSSI coordination — We integrate AI Act and LSSI (Law 34/2002) for cookies and e-commerce
- Technical documentation — We prepare Art. 11 documentation for high-risk e-commerce AI
AI Act obligations for E-commerce
AI Act obligations for e-commerce depend on the AI classification:
Limited-risk AI (chatbots, synthetic content):
- Inform users they are interacting with AI (Art. 50(1))
- Mark AI-generated synthetic content (Art. 50(2)-(4))
- These obligations enter into force on 2 August 2026
High-risk AI (credit scoring, insurance):
- Risk management system (Art. 9)
- Training data quality (Art. 10)
- Technical documentation and record-keeping (Art. 11)
- Transparency for deployers (Art. 13)
- Human oversight (Art. 14)
- Accuracy, robustness and cybersecurity (Art. 15)
- Conformity assessment (Art. 6 + Annex III)
- EU database registration (Art. 49)
Prohibited practices (Art. 5):
- Subliminal manipulation (Art. 5(1)(a)) — in force since 2 February 2025
- Exploitation of vulnerabilities (Art. 5(1)(b))
- Social scoring (Art. 5(1)(c))
Minimal-risk AI:
- No specific obligations
- Voluntary codes of conduct
Timeline: Art. 50 transparency obligations enter into force on 2 August 2026. Prohibited practices under Art. 5 have been in force since 2 February 2025. High-risk systems under Annex III must comply before 2 December 2027.
AI use cases in E-commerce and their classification
| Use case | AI Act classification | Applicable rule |
|---|---|---|
| Product recommendation engine | Minimal (generally) | GDPR + LSSI |
| Dynamic pricing | Minimal (generally) | GDPR + LSSI |
| Customer service chatbot | Limited risk | Art. 50(1) transparency |
| Synthetic content generation (reviews, images) | Limited risk | Art. 50(2)-(4) marking |
| Credit scoring for financing | High risk | Annex III, point 5(b) |
| Insurance pricing | High risk | Annex III, point 5(c) |
| AI dark patterns | Prohibited | Art. 5(1)(a) |
| Customer emotion recognition | High-risk (if not prohibited) | Annex III point 1(c) + GDPR Art. 9 |
Real enforcement cases in e-commerce
- AEPD — SEAT, €12,000 (2024) — Non-technical cookies without consent and no consent withdrawal (PS/00284/2024). Source: Confilegal
- AEPD — Guide on the use of cookies: AEPD
- AEPD — Guide to safe online shopping: AEPD
- AEPD — Decalogue for privacy policies: AEPD
- EDPB — Guidelines 8/2020 on social media targeting: EDPB
- EDPB — Cookie Banner Taskforce Report (2023): EDPB
AI Act compliance checklist for E-commerce
- Identify all AI uses in the e-commerce
- Classify each use under Annex III
- Verify no prohibited dark patterns (Art. 5(1)(a))
- Implement chatbot transparency (Art. 50(1))
- Mark AI-generated synthetic content (Art. 50(2)-(4))
- If high-risk: risk management system (Art. 9)
- If high-risk: technical documentation (Art. 11)
- If high-risk: conformity assessment and EU database registration
- Coordinate with GDPR: legal bases, data subject rights, Art. 22
- Coordinate with LSSI: cookie consent, consumer information
- Verify free and specific consent for non-technical cookies
- Implement right to object to profiling (Art. 21 GDPR)
Official sources
- Regulation (EU) 2024/1689 (AI Act): EUR-Lex
- Art. 50 (transparency): Digital Strategy
- Art. 5 (prohibited practices): AI Act Service Desk
- LSSI (Law 34/2002): BOE
- GDPR (Regulation (EU) 2016/679): EUR-Lex
Related resources
- AI Act Hub — Resource centre on the European AI Regulation
- AI Act Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- AI Act Compliance Checker — Self-assess your AI system
- AI & Data Regulation Service — Integrated advisory
- GDPR for E-commerce — Sectoral GDPR guide for e-commerce
This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.