EU AI Act obligation checklist for commerce teams
A practical, jargon-free checklist for commerce teams: what to inventory, how to classify it, and what to do before August 2, 2026.
Published 15 June 2026 · Last updated 22 July 2026 · BAICA Research
Why this guide exists
The EU AI Act is the world's first comprehensive law on artificial intelligence. It applies to any organisation placing an AI system on the EU market, whether the vendor is based inside the EU or not. Most commerce stacks in 2026 already include several AI systems in scope: recommender engines, search ranking, chatbots, dynamic pricing, fraud detection, content moderation, ad targeting, and generative product copy. The obligations depend on how you use the system, not just what the vendor sells you.
This checklist walks through the four things a commerce team needs to do to be defensible: build an inventory, classify each system by risk, decide provider or deployer for each, and document the controls. It is written for eCommerce, marketing, product, and operations leaders, not for lawyers.
Step 1: Inventory every AI system in your commerce stack
You cannot classify what you do not know exists. Start with a plain spreadsheet with one row per AI system and these columns: system name, vendor, business purpose, what data it processes, who the end user is, whether it makes or supports a decision that affects the customer, and whether it is customer-facing.
Common systems to look for:
- Product search and search ranking (in-house or vendor)
- Recommender systems on product, category, cart, and email surfaces
- Personalisation and audience segmentation
- Dynamic pricing and promotion optimisation
- Chatbots, customer service copilots, and voice agents
- Fraud detection and chargeback scoring
- Content moderation for reviews and user-generated content
- Generative product descriptions, images, and ad creative
- Forecasting and inventory allocation
- HR and recruitment tools used by the commerce team (these have their own strict rules)
Step 2: Classify each system by risk
The Act uses four risk tiers. In commerce, almost everything falls into two of them.
- Prohibited: systems that manipulate behaviour in harmful ways, exploit vulnerabilities of specific groups, or perform social scoring. Rare in commerce, but review any system that uses emotion detection on customers or employees, or that infers sensitive attributes to price differently.
- High-risk: mostly recruitment, worker management, credit scoring, and safety components. Uncommon in commerce, common in the HR tools your commerce team touches.
- Limited risk (transparency obligations): chatbots, generative content, and systems interacting with people. You must tell users they are interacting with an AI system or that content is AI-generated. This covers most commerce chatbots and most generative product content.
- Minimal risk: everything else, including most recommenders and search ranking. No specific obligations under the Act, but general product safety and consumer protection rules still apply.
Step 3: Decide provider or deployer for each system
A provider puts an AI system on the market under its own name. A deployer uses an AI system under its authority in a professional context. Most commerce companies are deployers of vendor systems, but you become a provider the moment you substantially modify a system, put it under your own brand, or repurpose it for a different use than the vendor documented.
Practical test: if the vendor's documentation clearly covers your use case and you have not fine-tuned or re-trained the model, you are a deployer. If you fine-tuned an open-source model on your catalogue and ship it as your feature, you are a provider for that system.
Step 4: Close the transparency and documentation gaps
- Every customer-facing chatbot needs a clear notice that the customer is interacting with an AI system. Add it to the first message, not buried in a policy.
- Every piece of AI-generated content that could be mistaken for human-generated should be labelled, especially review summaries, generated product descriptions, and generated imagery.
- Keep vendor documentation for every system: model card, intended use, known limitations, data sources. Ask for it in writing before the next renewal.
- Maintain a human oversight route for any system that affects the customer significantly, including a way for a person to review and reverse the decision.
- Log system behaviour to the extent your vendor allows. You will need this the first time a regulator or a customer asks why the system did what it did.
What to do this quarter
- Book a two-hour workshop with product, marketing, ops, and legal, and complete the inventory.
- Classify each row and mark the transparency gaps.
- Fix the customer-facing gaps first: chatbot notices, generative content labels, human-review routes.
- Send a documentation request to every AI vendor and put the responses in a shared folder.
- Re-run the inventory every quarter. New AI shows up faster than governance does.
Key dates
- February 2, 2025: prohibited practices in force
- August 2, 2025: rules for general-purpose AI models in force
- August 2, 2026: most obligations for high-risk and limited-risk systems in force
- August 2, 2027: full application, including remaining transitional provisions
Next: how to evaluate an AI vendor before you sign, and using customer data in AI without losing trust.
Put the guide to work.
Every guide is free and open-licensed. If a question keeps coming up in your team and we have not covered it, tell us and it goes on the list.