← All articles

The AI Act applies to your online shop. Yes, yours.

Chatbot, recommendations, AI-written product pages: your shop already uses AI, and the AI Act applies. What the regulation asks of an online retailer, and how to get started without panicking.

Dots Papers cover for the article on the AI Act and online shops

Try this: open the module list of your shop. A chatbot answering customers. Product recommendations. A tool that writes product pages or social posts. An anti-fraud filter. If you tick a single one of those boxes, your shop uses artificial intelligence systems. And since 2 August 2026, part of the European regulation on AI, the AI Act, applies very concretely to what you do.

The good news: for an online retailer, this is neither the panic nor the endless paperwork you may have been sold. It is mostly a matter of method. As consultants, this is how we frame the subject with our clients, within our artificial intelligence expertise, and where to start this week.

The AI Act for online retailers, in 30 seconds.

The AI Act in two minutes, the retailer version

The AI Act (EU regulation 2024/1689) is the first law in the world to frame the use of artificial intelligence. It classes AI systems by risk level and attaches obligations to each level. The timetable runs over several years, but one deadline concerns you directly: since 2 August 2026, the transparency obligations of Article 50 apply.

In practice, for an online shop, three ideas cover the essentials:

  1. You are concerned even if you developed nothing. The regulation distinguishes the provider, who creates the AI system, from the deployer, who uses it. A retailer installing an AI chatbot or a recommendation module is a deployer. Fewer obligations than the provider, but not zero.
  2. Transparency is the heart of it. A customer talking to an AI must be able to know it. AI-generated content must be identifiable as such. That is Article 50, and it is exactly the kind of thing an auditor, a partner or an informed customer can check on your site in two clicks.
  3. What you will be asked for first is proof. Knowing which AI systems run in your shop, what they do, on what basis, and what you have put in place. The day the question arrives, from an authority, a B2B customer or an insurer, “I am not really sure what my modules do” is the worst possible answer.

The real problem: you probably do not know what is running

It is the exact parallel with what we wrote about tracking that lies in silence: what nobody looks at degrades quietly. An average shop accumulates modules over the years. Some embed AI without saying so clearly. Others added it in an update. Nobody keeps the list.

A shelf of modules with one lighting up and a magnifying glass beneath it: the AI hidden in your back office
Only one module on the shelf contains AI, and nothing tells it apart from the others until someone looks.

Yet all AI Act compliance starts with a disarmingly ordinary question: which AI systems do you use? No reliable answer to that question, no compliance possible. It really is that simple.

The method: four steps, in order

Here is the approach we apply, and it fits on one page:

  1. Inventory. List everything on your shop that decides, predicts, classifies, recommends or generates: installed modules, connected SaaS services, tools your team uses (including ChatGPT for writing your product pages). This is the step everyone skips, and the only genuinely indispensable one.
  2. Qualify. For each system: what is your role, deployer in most cases, what risk level under the regulation, and while you are at it what GDPR legal basis. The two regulations answer each other, so handle both at once: if your day-to-day GDPR work is under control, half the job is already done.
  3. Work through the obligations. Each system, according to its level and your role, carries precise obligations, with an article of the regulation and a date of application. For most shops it comes down to transparency, informing and labelling, plus documentation. That is doable.
  4. Build the evidence. An up-to-date register, the measures in place, a log of what was done and when. The point is not the binder for the binder’s sake: it is being able to answer within 24 hours if the question comes.
A clipboard with four steps ticked, next to a binder of evidence
The four steps are only worth what they leave behind: a binder of evidence you can open in front of someone.

An immediate self-diagnosis, with no tool at all: export your module list and highlight every one where you cannot say whether it uses AI. Each highlight is a line in your future inventory. If you highlight half the list, you know why this deserves an hour this week.

Which approach? The honest comparison

There are several ways to handle this, and they do not address the same shops. Here is how we present them to our clients:

Approach What it gives you Who it suits
The home-made spreadsheet Free, and enough to start the inventory. But nobody keeps it up to date as modules are installed, and it knows neither the articles of the regulation nor the deadlines. Very small shop, few modules, zero budget.
A lawyer or specialist firm Essential for sharp questions and high-risk cases. But billed by time spent, and it will not live in your back office day to day: it will ask you for exactly the inventory you do not have. Complex situations, high-risk systems, disputes.
An AI governance platform Complete and multi-regulation, but built for large accounts: enterprise pricing, long deployment, and no knowledge of your shop or your modules. Groups and mid-caps with a dedicated compliance team.
A module inside the shop Detects AI systems directly in your installed modules, links each system to its obligations and generates the evidence from the back office. Fixed price, but limited to the shop’s scope. Retail SMEs: the shop is the subject.

These approaches combine rather well, in fact: the module keeps the inventory and the evidence day to day, the lawyer steps in on the cases that deserve it, working from a clean file rather than a blank page.

Tooling: getting this structured without spending weeks

Doing this inventory by hand in a spreadsheet is possible. Keeping it up to date at every module installation, at every update, over time: let us be honest, nobody does.

For our clients on PrestaShop, we use AI Act Ready. Full transparency, as always here: the module is published by Datafirefly Limited, the sister company of our agency. It does exactly the four steps above, inside the back office: a scanner compares your installed modules against a signature database covering roughly 90% of popular PrestaShop AI modules and 100% of Datafirefly’s own; systems that cannot be detected automatically (in-house AI, serverless API calls) are added to the register by hand, the scan being a starting aid rather than a compliance guarantee. A guided register then walks you through qualifying each system (role, risk level, GDPR legal basis), obligations appear per system with the article of the regulation and its date of application, and documents generate as PDFs in six languages, with a consolidated export ready to hand to an auditor. Data stays 100% on your own server.

A beam sweeps a grid of modules and reveals the one containing AI
What the scanner does: compare your installed modules against a signature database. Whatever it does not detect is added to the register by hand.

And the point that made us choose it, beyond the family connection: its product page says in black and white that it “does not replace a lawyer and does not guarantee your compliance”. A compliance tool promising turnkey compliance is lying to you. This one structures the work and saves you weeks; the final judgement stays human, and for sharp cases, legal. That is the right division of roles.

Visual of the AI Act Ready module for PrestaShop 8

AI Act Ready for PrestaShop 8

PrestaShop 9 compatibility is not covered at this stage. AI system scanner, guided register, obligations with the article of the regulation, PDF documents in six languages, auditor export. Data 100% local, multistore. €229 for the first year, then €69/year. 30-day refund.

See the module

What this says about something bigger

The AI Act, like the GDPR before it, will progressively become a commercial criterion. B2B buyers are starting to ask their suppliers for AI guarantees, insurers are taking an interest, and marketplaces will end up requiring attestations. Shops with a clean register will answer within the hour. The others will improvise.

Our advice fits in one sentence: treat the AI Act as an inventory to keep, not a threat to ignore. The initial effort is modest, and it is very largely recovered in credibility.

And once the inventory is in place, the subject becomes interesting again: knowing what actually works with AI in a small company, rather than enduring the regulation without ever getting anything out of the tool.

FAQ

I only use a chatbot supplied by a provider. Am I concerned?

Yes, as a deployer. Your obligations are limited but real: your customers must know they are talking to an AI, and you must know what the system does. The chatbot provider has its own obligations, which do not release you from yours.

I generate my product pages with AI. Is that a problem?

No, it is legal. The subject is transparency: generated content must be identifiable as such in the cases the regulation provides for, and the practice deserves a line in your inventory. Generating is not the risk; not knowing that you generate is.

What does a small shop actually risk?

The regulation provides for penalties proportionate to company size. But for an SME the most concrete risk lies elsewhere: a partner, a B2B customer or an insurer who asks for proof and does not get it. Compliance plays out in commercial relationships more often than before an authority.

Can Dotsland help?

Yes. Inventory of your AI systems, qualification, setting up the tooling and the transparency notices, consistent with your existing GDPR work. That is the core of our AI expertise. Get in touch, or start with the self-diagnosis above: highlighting your module list is an excellent wake-up call.

Want to apply this to your own business?

Get in touch →

Further reading

Leave a comment

Your email address will not be published. Required fields are marked *

3 × five =