Article 50 transparency obligations became enforceable on 2 August. High-risk duties were deferred to December 2027. Here is what that split means for stores running chatbots, AI merchandising and generated product content.
Two August 2026 was the date the EU AI Act was always going to matter. What arrived was not quite what the calendar promised in 2024, and the difference is worth understanding precisely, because a lot of the commentary published in the last fortnight gets it backwards.
The short version: the transparency obligations under Article 50 are now applicable and enforceable across the EU. The heavy high-risk obligations, which everyone spent two years preparing for, were deferred. If your compliance programme was built around high-risk classification, you have more time. If you assumed the deferral meant nothing happened on 2 August, you are wrong in the more expensive direction.
The Commission proposed the Digital Omnibus on AI in November 2025. It was adopted as Regulation (EU) 2026/1744 and came into force on 27 July 2026, five days before the original deadline.
| Obligation | Original date | Position after the Omnibus |
|---|---|---|
| Prohibited practices | 2 February 2025 | Unchanged, applicable |
| GPAI model provider duties | 2 August 2025 | Unchanged, with enforcement powers now live |
| Article 50 transparency | 2 August 2026 | Applicable and enforceable now |
| Annex III high-risk systems | 2 August 2026 | Deferred to 2 December 2027 |
| Annex I high-risk, AI in regulated products | 2 August 2027 | Deferred to 2 August 2028 |
| Penalty regime | 2 August 2026 | In effect |
The Omnibus also added a prohibition on AI-generated non-consensual intimate imagery under Article 5, and widened the AI Office's supervisory reach over vertically integrated AI providers.
The most common misreading in circulation right now is that the Omnibus postponed the AI Act. It postponed the high-risk chapter. Transparency and penalties arrived on schedule. This distinction is not academic, since the transparency duties are the ones that apply to nearly every ecommerce operation using AI.
Article 50 applies to systems in four situations, regardless of risk classification. In plain terms, for a store:
Systems that interact directly with people. Your support chatbot, your AI shopping assistant, your automated sizing or product finder. Users must be able to tell they are dealing with a machine, unless that is already obvious from context. The safe interpretation of obvious is narrow. A widget labelled Chat with us, staffed by a model, is not obvious.
Generated or manipulated content. AI-written product descriptions, generated lifestyle imagery, synthetic model photography, AI-generated video. Providers of generative systems have machine-readable marking obligations, and deployers have disclosure duties where content is published. The technical standards for marking are still being finalised through the Code of Practice, which is a reason to track developments rather than a reason to wait.
Deepfakes. Manipulated audio, image or video of real people must be disclosed as artificially generated. In commerce this most often shows up in synthetic spokesperson content and AI-altered testimonial video.
Emotion recognition and biometric categorisation. If any system in your stack scores emotional state or categorises people biometrically, the people exposed to it must be informed. Some session replay and in-store analytics vendors are closer to this line than their sales material suggests.
There is a carve-out worth knowing: the marking duty does not apply where the system performs only an assistive function for standard editing, or where it does not substantially alter the input data or its semantics. Grammar correction on copy a human wrote is not the same as generating the copy.
Most ecommerce teams do not have an AI inventory, which is the first problem. You cannot disclose what you have not catalogued.
This register overlaps heavily with your GDPR records of processing. Building them separately is duplicated work. We covered the earlier state of play in our May 2026 update on the AI Act and ecommerce.
Annex III high-risk classification now bites on 2 December 2027. For most ecommerce businesses the relevant Annex III category is not the storefront at all, it is employment. Tools used for recruitment, candidate screening, performance evaluation, task allocation, worker monitoring and promotion or termination decisions are high-risk by classification.
That matters because a growing number of retail and logistics operations use AI in workforce scheduling and performance management without ever categorising it as an AI project. The Commission published draft guidelines on high-risk classification in May 2026, which are currently the most usable document for substantiating your own classification.
There is also a transitional detail that is easy to miss. Systems placed on the market before the application date benefit from a grandfathering regime, provided the design remains unchanged. The threshold for a significant change has not been defined, which is a genuine gap in legal certainty and belongs in your product planning rather than in a lawyer's file.
For a typical DTC or B2B ecommerce operation in France, the UK selling into the EU, or Canada with EU customers, the practical August 2026 workload is small and the November 2027 workload is not. Do the inventory now while the scope is narrow, because doing it later means doing it under a deadline with more systems in play.
The penalty regime is live, and for the transparency obligations the exposure is meaningful enough that a two day audit is a rational investment.
We build AI and data compliance registers alongside the automation work that usually creates the exposure in the first place. See our workflow automation service or talk to us about a review.
Yes, where the system is placed on the EU market or its output is used in the EU. A UK or Canadian store selling to EU customers is in scope for the relevant obligations.
Where content is generated rather than merely edited, disclosure duties apply. Light assistive editing of human-written copy falls outside the marking duty. The technical marking standards are still being finalised, so track the Code of Practice.
Generally no. Product recommendation is not an Annex III category. Employment-related uses are, which is where most ecommerce companies actually have exposure.
The penalty regime became applicable alongside the transparency obligations. Exposure varies by breach type and is calculated on global annual turnover, which makes it material even for mid-sized operations.
No. Transparency and penalties apply now. The deferral applies to the high-risk chapter, and organisations that demobilised compliance programmes on the strength of the political agreement have work to restart.
This article is general information rather than legal advice. For classification decisions with material consequences, take advice from counsel qualified in the relevant jurisdiction.

On May 7, 2026, EU lawmakers agreed to delay parts of the AI Act. But the chatbot transparency rules were not delayed much. Here is what an ecommerce store actually has to do, and by when.

Most Shopify agency selection processes are driven by vibes and a sales call. Here is the framework we would use as buyers, what to actually ask, what the answers should sound like, and the specific red flags that predict a project going sideways.

The business case for Core Web Vitals on ecommerce sites, in numbers. Real conversion impact data from Vodafone, NDTV, Carpe, Rakuten, and 30 other case studies. What 100ms of LCP actually costs you per month.