Key Takeaways
- On 2 August 2026, the European Commission’s AI Office and national authorities began enforcing the AI Act. The same date brought Article 50 transparency rules into application: users must know when they talk to AI, and certain AI-generated or altered content must be labelled and machine-readable. (European Commission press release)
- For Shopify merchants, the practical hit is storefront AI: support chatbots, sales agents, product copy tools, image generators, virtual try-on, and review automation.
- You are often a deployer (you use AI under your brand), not a model trainer. Providers still owe design and marking duties; you still owe clear labels where the Act puts the duty on deployers, and you still choose vendors who can prove compliance. (Commission Article 50 FAQ)
- High-risk AI rules were postponed by the AI Omnibus (broadly 2 December 2027 / 2 August 2028). Transparency was not postponed. New bans on certain non-consensual sexual content systems apply from 2 December 2026.
- AI disclosure sits next to your existing EU stack: cookie consent, GDPR rights, consumer withdrawal, and related duties. One storefront, one trust promise.
What went live on 2 August 2026
On 31 July 2026 the Commission confirmed that from 2 August 2026 it would start enforcing the AI Act together with national authorities. On the same date, new transparency requirements apply: certain AI systems must tell people when they interact with AI, and when content was generated or altered by AI. (Commission news)
In the Commission’s own summary:
- Chatbots and other interactive AI must make clear that the user deals with AI, not a human.
- Deepfakes (AI-edited or AI-generated images, video, or audio) must be labelled.
- AI-generated or altered content must also carry machine-readable marks so detection tools can spot them more easily.
The stated goal is less deception and manipulation, clearer business obligations, and a practical path to show compliance. The Commission also published a first list of more than 180 organisations that signed the Code of Practice on transparency of AI-generated content.
This post is the enforcement follow-up to our earlier guide, Preparing for EU AI Act Transparency: What Shopify Sellers Need to Know. Prep mode is over. Disclosure mode is on.
Article 50 in plain language
Article 50 of the AI Act sets transparency obligations that apply even when a system is not “high-risk.” In practice it covers four situations:
- Direct interaction with people (chatbots, agents, avatars).
- Synthetic content (text, image, audio, video) that needs machine-readable marking so content is detectable as AI-generated or manipulated.
- Emotion recognition or biometric categorization (deployers must inform people when they use these systems).
- Deepfakes and certain AI-generated or manipulated text on matters of public interest published without adequate human review or editorial control (deployer labelling duties).
Lets go into more detail.
Chat and agents (interaction)
Providers must design systems that interact directly with natural persons so people know they interact with AI, unless it is obvious.
The guidelines treat the “obvious” exception narrowly. Notice should arrive from the start of the first interaction, in a clear, distinguishable way, and with accessibility in mind. Background, machine-to-machine, or non-interactive automation sits outside this limb.

Generative outputs (marking)
Providers of systems that generate synthetic audio, image, video, or text must mark outputs in a machine-readable, detectable way.
Some narrow technical outputs fall outside (for example certain short symbol strings, source code, pure machine-to-machine outputs, or closed industrial loops that never expose final output to humans). Marketing assets that customers see are not “closed loop.”

Deepfakes and public-interest text (deployer labels)
When you put deepfake-style media into the market under your authority, or publish certain AI text on public-interest topics without proper human editorial control, deployer labelling duties apply.
“We used a third-party tool” does not erase your brand’s role if the system runs under your control for business use.

Provider vs deployer: where Shopify brands sit
A Shopify merchant who installs a chat app, an AI copywriter, or an image generator under the store brand is typically a deployer. If you white-label a custom agent under your own trademark as a product you sell to others, you may also step into provider territory. Cross-border fact: providers outside the EU can still fall in scope when output is used in the EU.
Practical takeaway: inventory every AI touchpoint, map provider vs deployer duties with counsel, and prefer apps that ship built-in disclosure UI, watermarks / content credentials, and written compliance docs. Our roundup of GDPR-minded AI agents for Shopify is a useful starting filter; add AI Act transparency to the RFP checklist.
Storefront checklist for merchants
Pair this with classic privacy transparency. People already expect clear notices on data use; see our guide on transparency requirements across major privacy laws. AI disclosure is the same habit in a new surface.
What did not fully land yet
The AI Omnibus postponed parts of the high-risk regime so industry and authorities could prepare:
- High-risk rules for many stand-alone systems: toward 2 December 2027
- High-risk AI integrated into certain regulated products: toward 2 August 2028
It also introduces new prohibitions on AI systems that generate non-consensual sexually explicit content and child sexual abuse material, with application from 2 December 2026 (per the Commission’s enforcement announcement timeline).
What this means for you: do not confuse “high-risk delayed” with “AI free-for-all.” Chat disclosure and content transparency are live. Use the high-risk delay to finish vendor contracts, risk reviews, and documentation, not to hide bots behind human masks.
How enforcement works
From the Commission’s enforcement package:
- The AI Office enforces rules for providers of general-purpose AI (GPAI) models, including advanced models with systemic-risk duties (documentation, copyright policy, training-content summary, and extra risk measures for the most capable models).
- Responsibility for transparency and prohibited practices is shared:
- AI Office for AI systems offered by the same provider as the underlying GPAI model, and for systems integrated into very large online platforms / search engines designated under the DSA.
- National competent authorities for other AI systems.
- European Data Protection Supervisor for AI used by EU institutions and bodies.
- People and businesses can use the Commission’s complaint, whistleblower, and downstream provider channels.
Merchants will feel enforcement first through app stores, platforms, and customer complaints, then through national authorities as capacity ramps up. Waiting for a headline fine is a poor strategy.
Trust is the product
Hidden AI fails the same way a forced cookie wall or a buried privacy policy fails: the shopper only learns the truth after they have already trusted you.
Consentmo’s lane is clear, lawful choice and notice on Shopify: cookie banners, preference control, privacy request flows, and consumer-facing compliance pages. AI labels belong in that same design system: visible, early, honest.
When your policies and cookie page stay accurate after every scan, you free the team to fix AI UX instead of chasing stale legal copy. That is exactly why we shipped the Smart Cookie Policy Page and the Privacy Center for automated privacy requests.
Your wider EU compliance stack
AI Act transparency is one layer. EU customers still experience your whole store as a single promise. Keep these live duties on the same dashboard as your AI inventory.
1. Cookies, ePrivacy, and Consent Mode
Lawful consent before non-essential tracking, purpose-bound tags, and records you can defend. Google Consent Mode still depends on a real consent signal. Refresh the basics with our Consent Mode and GDPR guide.
2. GDPR data-subject rights
Access, erasure, portability, and objection need a path shoppers can find without emailing a void.
Wire requests through a single Privacy Center and keep your GDPR checklist current against EDPB-oriented 2026 updates.

3. DSA touchpoints (if you host or amplify UGC)
If customers post reviews, Q&A, or community content, know your notice-and-action and trader-transparency duties. AI moderation tools here must themselves respect transparency and prohibited-practice rules.
4. EU right of withdrawal (consumer law)
Under EU consumer rules for distance sales, customers generally get a 14-day cooling-off period to cancel without giving a reason. For goods, the clock usually runs from delivery; for services, from contract conclusion. Sellers must inform customers about the right and the cost of return before purchase. Official overview: Your Europe, Returns and the right of withdrawal.
Exceptions exist (for example clearly personalised goods, certain perishable items, unsealed sealed software, and digital content after performance starts with express acknowledgment). Exceptions need plain-language pre-contract copy, not a PDF graveyard.
Interface reality in 2026: many stores now also need a clear withdrawal button / page path so the right is as easy to exercise as checkout. We covered the merchant workflow with EU Withdrawal Page and Button by Consentmo, plus branded confirmation mail in our custom sending domain for EU withdrawal emails.

AI that drafts order or support replies must never invent a stricter returns policy than the law and your published terms allow.
5. Cross-border privacy (US states and beyond)
If you sell into both the EU and US state regimes, geotargeted notices and consent still matter. AI tools that personalise by region must respect the same location logic as your banner.
6. AI Act transparency
Disclose interactive AI, label synthetic media where required, pick vendors who implement machine-readable marks, and document your stack.
Bottom line: cookie choice, privacy requests, withdrawal, and AI labels are four faces of one rule: no surprises after the click.
30-minute action plan
- List every AI app on the store (chat, search, recommendations, copy, image, reviews, Sidekick-style helpers).
- Screenshot the customer journey. Is AI named in the first message and in the UI chrome?
- Email each vendor: Article 50 disclosure defaults, machine-readable marking, Code of Practice participation, DPA, and EU subprocessors.
- Fix copy: remove “talk to our team” when the only reply is a model; add honest AI labels.
- Align legal pages: privacy notice, cookie policy, AI mention where you process data through models, withdrawal instructions.
- Run a compliance pass on consent and request flows (Consentmo Compliance Score is built for the non-AI half of this audit so you can focus engineering time on chat and creative tools).
- Brief support so humans never contradict AI disclosures or withdrawal rights in tickets.
Conclusion
2 August 2026 moved the EU AI Act from calendar entry to live enforcement, with transparency at the centre: people deserve to know when a machine speaks and when media is synthetic.
Shopify merchants do not need to train frontier models to be in scope. You need honest storefronts, careful vendors, and the same discipline you already apply to cookies, GDPR, and the 14-day EU right of withdrawal.
Ship disclosure the way you ship checkout: clear, early, and consistent. If you want help locking the consent, policy, privacy-request, and withdrawal layers while you clean up AI UX, Consentmo is built for that stack on Shopify.
This article is general information for merchants, not legal advice. Confirm duties for your exact systems with qualified counsel and the latest Commission guidelines.



