Home
Services

E-Commerce Engineering

  • Shopify Theme DevelopmentOptimized Shopify 2.0 theme
  • Shopify App DevelopmentPrivate app for your store
  • Headless Shopify SolutionsLightning-fast Next.js + Hydrogen stores
  • Platform Migration to ShopifyMove to Shopify smoothly
  • Shopify Speed OptimizationImprove Core Web Vitals

Custom Software Development

  • SaaS & Web Applications DevelopmentFull-stack apps with modern frameworks
  • API Development & System IntegrationConnect systems via APIs

Workflow & Data Operations

  • Workflow AutomationEliminate repetitive manual tasks
  • Data Analytics & DashboardsTurn data into dashboards
  • Technical SEO EngineeringSchema, audits, and programmatic SEO

Trusted by leading enterprises in France, UK & Canada.

View all services
BlogAbout
|
Contact

Ready to engineer the future?

Whether you need a full engineering squad or technical consultancy, let's discuss your roadmap.

Book a Technical SEORequest a Migration AuditHire Dedicated Developer

High-end Shopify engineering for brands that refuse to compromise on performance.

Copyright © 2026 Sentinu Solutions.
All rights reserved.

Services

  • Custom App Development
  • Headless Shopify
  • Shopify Migration
  • Shopify Performance Audits

Start Project

  • Shopify Ecommerce Engineering
  • Custom Software Development
  • Automation Workflow Services

Legal

  • Privacy Policy
  • Terms of Service
  • Legal Notice

Connect

  • facebook
  • instagram
  • linkedin
Home/Blog/The EU AI Act on 2 August 2026: What Actually Applies to Ecommerce Now
Growth StrategyEcommerce Development

The EU AI Act on 2 August 2026: What Actually Applies to Ecommerce Now

Article 50 transparency obligations became enforceable on 2 August. High-risk duties were deferred to December 2027. Here is what that split means for stores running chatbots, AI merchandising and generated product content.

Aug 4, 20267 min read

Share this article

Contents

  • What the AI Omnibus changed
  • The four transparency duties, translated for ecommerce
  • An audit you can run this week
  • The high-risk deferral, and why it is not a holiday
  • What we are telling clients
  • Frequently asked questions

Share this article

Contents

Contents

  • What the AI Omnibus changed
  • The four transparency duties, translated for ecommerce
  • An audit you can run this week
  • The high-risk deferral, and why it is not a holiday
  • What we are telling clients
  • Frequently asked questions

Two August 2026 was the date the EU AI Act was always going to matter. What arrived was not quite what the calendar promised in 2024, and the difference is worth understanding precisely, because a lot of the commentary published in the last fortnight gets it backwards.

The short version: the transparency obligations under Article 50 are now applicable and enforceable across the EU. The heavy high-risk obligations, which everyone spent two years preparing for, were deferred. If your compliance programme was built around high-risk classification, you have more time. If you assumed the deferral meant nothing happened on 2 August, you are wrong in the more expensive direction.

What the AI Omnibus changed

The Commission proposed the Digital Omnibus on AI in November 2025. It was adopted as Regulation (EU) 2026/1744 and came into force on 27 July 2026, five days before the original deadline.

ObligationOriginal datePosition after the Omnibus
Prohibited practices2 February 2025Unchanged, applicable
GPAI model provider duties2 August 2025Unchanged, with enforcement powers now live
Article 50 transparency2 August 2026Applicable and enforceable now
Annex III high-risk systems2 August 2026Deferred to 2 December 2027
Annex I high-risk, AI in regulated products2 August 2027Deferred to 2 August 2028
Penalty regime2 August 2026In effect

The Omnibus also added a prohibition on AI-generated non-consensual intimate imagery under Article 5, and widened the AI Office's supervisory reach over vertically integrated AI providers.

⚖️

The most common misreading in circulation right now is that the Omnibus postponed the AI Act. It postponed the high-risk chapter. Transparency and penalties arrived on schedule. This distinction is not academic, since the transparency duties are the ones that apply to nearly every ecommerce operation using AI.

The four transparency duties, translated for ecommerce

Article 50 applies to systems in four situations, regardless of risk classification. In plain terms, for a store:

Systems that interact directly with people. Your support chatbot, your AI shopping assistant, your automated sizing or product finder. Users must be able to tell they are dealing with a machine, unless that is already obvious from context. The safe interpretation of obvious is narrow. A widget labelled Chat with us, staffed by a model, is not obvious.

Generated or manipulated content. AI-written product descriptions, generated lifestyle imagery, synthetic model photography, AI-generated video. Providers of generative systems have machine-readable marking obligations, and deployers have disclosure duties where content is published. The technical standards for marking are still being finalised through the Code of Practice, which is a reason to track developments rather than a reason to wait.

Deepfakes. Manipulated audio, image or video of real people must be disclosed as artificially generated. In commerce this most often shows up in synthetic spokesperson content and AI-altered testimonial video.

Emotion recognition and biometric categorisation. If any system in your stack scores emotional state or categorises people biometrically, the people exposed to it must be informed. Some session replay and in-store analytics vendors are closer to this line than their sales material suggests.

There is a carve-out worth knowing: the marking duty does not apply where the system performs only an assistive function for standard editing, or where it does not substantially alter the input data or its semantics. Grammar correction on copy a human wrote is not the same as generating the copy.

An audit you can run this week

Most ecommerce teams do not have an AI inventory, which is the first problem. You cannot disclose what you have not catalogued.

  1. List every AI system touching customers. Include the ones your vendors run on your behalf. Support chat, recommendation engines, AI merchandising, search relevance, review summarisation, generated copy tools, generated imagery, voice systems.
  2. Classify each against the four Article 50 situations. Most stores find between three and eight systems in scope and are surprised by at least two.
  3. Check what is currently disclosed. Open your own site as a customer. Does the chat widget say it is AI before the first message, or after you ask? Is generated imagery labelled anywhere a buyer would see it?
  4. Identify your role for each system. Provider or deployer. If you built it, you are likely a provider with the fuller obligation set. If you subscribe to it, you are usually a deployer, but check the contract, since some vendors push obligations downstream.
  5. Fix the disclosures. These are usually small copy and interface changes rather than engineering projects. The disproportionate cost is discovering the systems, not labelling them.
  6. Write it down. Maintain a register of AI systems, roles, disclosures and vendor contacts. This is what you will need if a national authority asks, and it is what makes December 2027 tractable.
Enforceable now: Article 50 transparency for chatbots and AI content. High-risk duties deferred to December 2027, still plan the register.
📁

This register overlaps heavily with your GDPR records of processing. Building them separately is duplicated work. We covered the earlier state of play in our May 2026 update on the AI Act and ecommerce.

The high-risk deferral, and why it is not a holiday

Annex III high-risk classification now bites on 2 December 2027. For most ecommerce businesses the relevant Annex III category is not the storefront at all, it is employment. Tools used for recruitment, candidate screening, performance evaluation, task allocation, worker monitoring and promotion or termination decisions are high-risk by classification.

That matters because a growing number of retail and logistics operations use AI in workforce scheduling and performance management without ever categorising it as an AI project. The Commission published draft guidelines on high-risk classification in May 2026, which are currently the most usable document for substantiating your own classification.

There is also a transitional detail that is easy to miss. Systems placed on the market before the application date benefit from a grandfathering regime, provided the design remains unchanged. The threshold for a significant change has not been defined, which is a genuine gap in legal certainty and belongs in your product planning rather than in a lawyer's file.

What we are telling clients

For a typical DTC or B2B ecommerce operation in France, the UK selling into the EU, or Canada with EU customers, the practical August 2026 workload is small and the November 2027 workload is not. Do the inventory now while the scope is narrow, because doing it later means doing it under a deadline with more systems in play.

The penalty regime is live, and for the transparency obligations the exposure is meaningful enough that a two day audit is a rational investment.

🛡️

We build AI and data compliance registers alongside the automation work that usually creates the exposure in the first place. See our workflow automation service or talk to us about a review.

Frequently asked questions

Does the AI Act apply if my company is outside the EU?

Yes, where the system is placed on the EU market or its output is used in the EU. A UK or Canadian store selling to EU customers is in scope for the relevant obligations.

Do I have to label AI-written product descriptions?

Where content is generated rather than merely edited, disclosure duties apply. Light assistive editing of human-written copy falls outside the marking duty. The technical marking standards are still being finalised, so track the Code of Practice.

Is my recommendation engine high-risk?

Generally no. Product recommendation is not an Annex III category. Employment-related uses are, which is where most ecommerce companies actually have exposure.

What are the penalties?

The penalty regime became applicable alongside the transparency obligations. Exposure varies by breach type and is calculated on global annual turnover, which makes it material even for mid-sized operations.

Does the deferral to December 2027 mean I can stop work?

No. Transparency and penalties apply now. The deferral applies to the high-risk chapter, and organisations that demobilised compliance programmes on the strength of the political agreement have work to restart.

This article is general information rather than legal advice. For classification decisions with material consequences, take advice from counsel qualified in the relevant jurisdiction.

Related Topics

eu-ai-actcompliancegdprecommerceai

Related posts

View all articles
EU AI Act for Ecommerce After the May 2026 Delay: What's Still Mandatory, What Got Pushed, and What to Do Before December
Growth StrategyMay 21, 2026

EU AI Act for Ecommerce After the May 2026 Delay: What's Still Mandatory, What Got Pushed, and What to Do Before December

On May 7, 2026, EU lawmakers agreed to delay parts of the AI Act. But the chatbot transparency rules were not delayed much. Here is what an ecommerce store actually has to do, and by when.

11 min read
How to Choose a Shopify Agency in 2026 (and the Red Flags to Walk Away From)
Growth StrategyJun 30, 2026

How to Choose a Shopify Agency in 2026 (and the Red Flags to Walk Away From)

Most Shopify agency selection processes are driven by vibes and a sales call. Here is the framework we would use as buyers, what to actually ask, what the answers should sound like, and the specific red flags that predict a project going sideways.

16 min read
Core Web Vitals and Conversion: The Ecommerce Data Nobody Wants to Hear
Performance OptimizationFeb 27, 2026

Core Web Vitals and Conversion: The Ecommerce Data Nobody Wants to Hear

The business case for Core Web Vitals on ecommerce sites, in numbers. Real conversion impact data from Vodafone, NDTV, Carpe, Rakuten, and 30 other case studies. What 100ms of LCP actually costs you per month.

13 min read