On Sunday, 2 August 2026, the transparency rules in Article 50 of the EU AI Act start to apply. If your store runs a chatbot that talks to shoppers in the EU, the short version is this: the shopper has to be told they are talking to a machine, at the first interaction, in a way they can actually notice. The European Commission confirmed the date and the lack of a general grace period in its Article 50 FAQ, last updated 20 July 2026.
Most store owners reading this will need to change one thing: the first message their support bot sends. That is genuinely it. But the details around who is responsible, and which of your AI content is in scope, are worth ten minutes of your time.

What actually applies on 2 August
Article 50 covers four separate duties. Only some of them touch a typical online store.
Article 50(1) requires that AI systems interacting directly with people are designed so those people know they are dealing with AI, unless it is obvious. Per the Commission FAQ, four criteria have to be met together: it has to be an AI system, designed for a genuine two-way exchange rather than just collecting data or firing back canned responses, communicating directly with the person rather than through a human, and interacting with a natural person. Systems running purely in the background or machine-to-machine are out of scope.
Article 50(2) requires providers of generative AI systems to mark synthetic audio, image, video and text in a machine-readable format so it can be detected as AI-generated. This is the watermarking duty, and it lands on the company that builds the model or system, not on you for using it.
Article 50(3) covers emotion recognition and biometric categorisation. Rare in retail, but if you have installed in-store camera analytics that infers mood or demographics, read it.
Article 50(4) requires deployers to label AI-generated text published to inform the public on matters of public interest, where it has not had human review or editorial control.
Do not skip the provider vs deployer distinction
This is where most of the panic comes from, and it is mostly misplaced.
The Commission FAQ is explicit that the duties in Article 50(1), (2) and (5) sit with providers, meaning whoever develops the AI system, or has it developed, and places it on the EU market under their own name or trademark. Deployers, meaning organisations using an AI system under their own authority, carry the duties in Article 50(3) and 50(4).
So if you installed a support bot from an established vendor and you are running it broadly as sold, that vendor is the provider and the chatbot disclosure obligation is theirs to build. Your job is to check they have done it.
You become a provider yourself if you put an AI system on the market under your own name or trademark, or have one developed for you. A custom bot your agency built on top of an LLM API and shipped as “the AcmeStore Assistant” is a very different position from a stock Tidio or Intercom widget. The Commission also notes that providers established outside the EU are in scope if the output of their AI system is used in the EU, so a Toronto or Sydney merchant selling into Europe does not get to opt out on geography.

The “obvious” exception is narrower than you think
Article 50(1) does not apply where it is obvious the person is dealing with AI. Merchants love this clause. The Commission does not.
The FAQ states the exception “should be interpreted in a restrictive manner, given that it deprives people of transparency,” and sets the test as an average person who is reasonably well-informed, circumspect and observant. A widget labelled “Chat” with a human-looking avatar and a first-name persona does not clear that bar. A widget that opens with “Hi, I’m an AI assistant” does.
The practical fix costs nothing. Put the disclosure in the opening message, not buried in a terms link. Make it perceivable without hovering or clicking. The FAQ also requires the notification to comply with accessibility requirements, which in practice means screen readers need to pick it up too. If you are already working through the interface side of this, our e-commerce security checklist for small stores covers the adjacent front-end hygiene most stores skip.
Your AI product descriptions are probably fine
Here is the part nobody is saying clearly. Article 50(4) applies to published AI text that informs the public on matters of public interest. The Commission lists the categories: politics and democratic processes, public administration, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, and economic, financial, scientific or cultural developments relevant to public debate.
A machine-drafted description of a running shoe is not any of those. Neither are your category pages or your abandoned-cart emails.
There is a second escape hatch even for in-scope text: content that has undergone human review or editorial control does not need labelling. But the FAQ is specific that superficial checks do not count. Spell-checking is not review. Deliberate examination of the substance by someone with relevant knowledge is, as is control by a responsible editorial entity with the authority to approve, alter or reject content on substantive grounds.
The grey zone for merchants is blog content. If you publish AI-drafted articles about, say, product safety recalls or environmental claims, that can touch consumer safety and environmental protection. Either put a human editor on it with real sign-off, or label it.
What the Digital Omnibus changed last week
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, according to law firm Lewis Silkin’s summary. It is the first formal set of amendments to the AI Act since 2024, and it did delay things. Just not this thing.
Stand-alone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027. Systems embedded in products under Annex I moved to 2 August 2028. Article 50’s core transparency duties did not move.
The one Article 50 concession is narrow: the machine-readable marking obligation in Article 50(2) gets a grace period to 2 December 2026, but only for AI systems placed on the market before 2 August 2026. Anything placed on the market on or after 2 August complies immediately. That is a supplier problem, not a merchant problem, but it is worth knowing when your vendor tells you they have until December.

What the fines look like
Up to 15 million euros or 3% of total worldwide turnover for the preceding financial year, whichever is higher, per the Commission FAQ. The same page notes proportionality can be taken into account for SMEs and small mid-cap companies.
Enforcement runs through national market surveillance authorities in each member state, not through the EU AI Office, which has a limited role covering systems built on general-purpose AI models where the same entity provides both, or systems inside a very large online platform designated under the DSA. In practice that means the regulator you hear from is national, and enforcement capacity varies a lot by country. Nobody should plan around a headline fine on day one. Nobody should plan around never being asked, either.
Do these five things before Sunday

- Open your own chatbot as a customer. Read the first message. If it does not say it is AI, fix that message today.
- Email your chatbot vendor one question: are you the provider under Article 50(1), and what have you shipped for it? Keep the reply.
- List every AI touchpoint on the site. Support bot, product recommender, sizing assistant, review summariser, AI search. Only the ones holding a genuine two-way exchange with a person are in scope for 50(1).
- Check whether your blog touches public-interest topics. If AI drafts it and nobody with subject knowledge reviews it, add real editorial review or add a label.
- Write down what you decided and why. A one-page note dated this week is the cheapest evidence you will ever produce. The Commission expects providers and deployers not signed up to the voluntary Code of Practice on Transparency of AI-generated content to demonstrate compliance by other adequate means, and warns they may face more requests for information.
Stores already building for AI-driven traffic have most of this mapped anyway. If that is you, our guide on how to prepare your store for AI shopping agents pairs well with this, because the same inventory of AI touchpoints serves both jobs.
The takeaway
This is a labelling law, not a ban. Nobody is telling you to switch off your bot. They are telling you to stop letting shoppers think “Sarah from support” is a person. For most stores that is a one-line copy change and a paper trail. Do it this week and stop thinking about it.
Sources
- European Commission, Transparency obligations under Article 50 of the AI Act (FAQ), last updated 20 July 2026
- European Commission, Guidelines on Transparency of AI-Generated Content
- European Commission, Code of Practice on Transparency of AI-generated content
- EU Artificial Intelligence Act, Article 50 full text
- Lewis Silkin, The Digital Omnibus on AI enters into force today, 27 July 2026
- Digital Omnibus on AI, Official Journal of the European Union, published 24 July 2026
This article summarises publicly available regulatory guidance. It is not legal advice. If you sell into the EU at scale, have a qualified lawyer review your position.
Last reviewed: 29 July 2026
Affiliate disclosure: E-Comm Partners may earn a commission from links on this site, at no extra cost to you. This does not influence which tools or regulations we cover.









