Most of what e-commerce does with AI is minimal or limited risk. Recommenders, search ranking, demand forecasting, dynamic pricing on products - none of these are named in Annex III. The exposure sits in three narrower places, and two of them are in physical stores rather than online.
Where online retail actually lands
| System | Tier | Note |
|---|---|---|
| Product recommenders, search ranking, personalisation | Minimal | Not an Annex III area. GDPR and the DSA are your real constraints |
| Dynamic pricing on products | Minimal | Pricing a product is not evaluating a person |
| Support chatbot / shopping assistant | Limited | Article 50 disclosure - live now |
| AI-generated product imagery or copy | Limited | Article 50(2) content marking - see marketing |
| Buy-now-pay-later / credit decisioning | High-risk | Annex III 5(b) - creditworthiness. See fintech |
| Facial recognition in store | High-risk | Annex III 1 - remote biometric identification, where lawful at all |
| Biometric categorisation by protected attributes | High-risk | Annex III 1 - inferring age, gender, ethnicity from faces |
| Emotion detection on shoppers | Limited + disclosure | Article 50(3). On staff it is prohibited outright under Article 5 |
| Fraud / chargeback scoring | Usually not high-risk | Annex III 5(b) carves out fraud detection - but only detection |
The single question that moves an e-commerce system from minimal to high-risk: is a person being evaluated, or a product? Ranking SKUs is fine. Scoring the shopper's creditworthiness, or inferring attributes from their face, is not.
The BNPL trap
Plenty of retailers have added instalment payments without thinking of themselves as lenders. If your platform - or a model you operate - decides or materially influences whether a customer is offered credit, that is Annex III point 5(b), the named high-risk case. It profiles individuals, so Article 6(3) is closed.
Where the provider is a third party like Klarna, the credit decision is usually theirs and you are a deployer. Where you score customers yourself before passing them on, look carefully - "materially influences the decision" counts as deciding.
In-store is where the real risk is
Emotion detection on staff is prohibited, not regulated. Article 5 bans emotion inference in the workplace outright. Retail analytics packages sometimes bundle "staff engagement" or "service quality" scoring from camera feeds - that is the feature to switch off today.
Demographic inference from cameras - estimating a shopper's age, gender or ethnicity - is biometric categorisation under Annex III point 1, and where it touches sensitive or protected attributes it may not be permitted at all. Vendors sell this as "audience analytics"; the label doesn't change the classification.
Footfall counting without identification is generally fine. Counting bodies is not identifying people.
What every retailer owes today
- One sentence in the shopping assistant's greeting saying it's an AI
- Visible labelling of AI-generated product imagery, and a check that provenance metadata survives your CDN pipeline
- An Article 4 literacy session for merchandising, CX and store-ops staff, minuted
- An audit of any in-store camera analytics for emotion or demographic inference
- A dated note of which systems you assessed and what you concluded
The AI Act sits on top of the DSA, the GDPR and consumer law here rather than replacing them. A recommender can be minimal risk under the AI Act and still carry DSA transparency duties if you're a large platform. Reglynn reports flag the overlaps rather than treating each regime as a separate project.
Ranking products, or scoring people?
That single question decides your tier. The free check settles it per feature.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.