Two years after the EU AI Act entered into force, the regulation becomes broadly applicable today. That sentence has been written in future tense by compliance teams across Europe for the better part of two years. It is now present tense.
The European Commission confirmed yesterday that the AI Office is now operational in its full enforcement capacity. The AI Act’s transparency provisions, the set of rules that most directly affect how ecommerce brands, agencies, and platforms communicate with EU consumers about AI, are among the rules now active.
What the Transparency Rules Require
The AI Act’s transparency obligations, set out in Article 50, apply to three categories of AI system directly relevant to ecommerce.
The first category is AI systems that interact directly with people. Any system deployed to interact with natural persons must make clear to those people that they are interacting with an AI, unless the context makes it obvious. For ecommerce, this means every AI chatbot deployed on a website, every AI customer service agent in a messaging app, and every virtual assistant answering product questions must identify itself as AI. The disclosure must happen at the start of the interaction, not buried in a footer or accessible only if the user actively asks.
The second category covers AI systems that generate synthetic audio, image, video, or text content intended to be publicly disseminated. Providers of these systems must ensure outputs are marked in machine-readable format, and deployers must disclose when AI-generated content is published. In an ecommerce context, this covers product images generated by AI tools, lifestyle photography assembled using generative AI, marketing copy produced by language models and published on product pages, and advertising creative built using tools like Adobe Firefly, Midjourney, or platform-native AI creative suites.
The third category is deepfakes specifically. Where AI-generated content creates a realistic representation of real people, places, or events that do not exist, it must be labeled as AI-generated. This is the provision that generated the most controversy when EU retailers lobbied the Commission to exempt product images from its scope. That exemption was not granted in absolute terms.
What the July 20 Guidelines Say
The Commission published its guidelines on transparency obligations for providers and deployers of certain AI systems on July 20, giving businesses twelve days before today’s enforcement start.
On chatbot disclosure: the obligation applies to all AI systems designed to interact with people. The disclosure must be made at the beginning of the interaction. Generic footer text or privacy policy references do not satisfy the requirement. The guidelines explicitly state that the disclosure must be clear and understandable to the average user.
On AI-generated content: the machine-readable marking requirement applies to content generated by covered systems. This includes image generation tools, text generation tools used to create published content, and video generation tools. The marking can be implemented through metadata standards such as C2PA, which we covered in the Google AI ad creative piece earlier this week.
On deepfakes: the visible disclosure requirement applies when AI-generated content creates a realistic depiction that could be mistaken for real content of real people, places, or events. A clearly stylized AI image that no viewer would mistake for a photograph is treated differently from a photorealistic product image featuring an AI-generated model.
The Enforcement Architecture
The AI Office can request technical documentation, evaluate models, require corrective measures, and issue fines for non-compliance. For the transparency provisions specifically, enforcement falls primarily to national authorities. The fine structure for transparency violations is up to 15 million euros or 3% of global annual turnover, whichever is higher.
There is also a new complaints mechanism. The Commission published an AI Act complaints tool this week, allowing individuals and organizations to submit complaints to the AI Office about potential violations.
The existence of this tool means that compliance failures are no longer dependent on regulator-initiated inspection. Any user who encounters an AI chatbot that does not identify itself, or who believes they have been deceived by undisclosed AI-generated content, now has a formal channel to report it.
What Has Not Changed Today
The high-risk AI system obligations do not apply today. Those provisions apply from December 2, 2027 for high-risk use cases in areas like biometrics, employment, and migration, and from August 2, 2028 for high-risk systems embedded in regulated products.
The AI Omnibus simplification, which entered into force on July 27, extended these timelines as part of the Commission’s effort to reduce compliance burden.
The Timeline You Should Pay Attention To
Active and enforceable now: chatbot disclosure at the start of every customer-facing AI interaction. Machine-readable marking on AI-generated content. Visible disclosure on deepfake content.
Coming December 2026: prohibition on AI nudification systems, relevant for any brand using AI-generated human imagery.
Coming December 2027: high-risk AI system obligations for employment, biometrics, credit, and other sensitive areas. For ecommerce brands using AI for customer scoring, pricing personalization based on individual characteristics, or hiring decisions, these provisions will require conformity assessments and documentation.
Our Take
The EU Just Turned on the Enforcement Engine. The Compliance Window Closed Two Years Ago.
Today’s enforcement start is not a surprise. The AI Act was published in 2024, the transparency provisions were widely covered, and the two-year implementation period was precisely designed to give businesses time to prepare.
The compliance question for most ecommerce operators is not whether they knew this was coming but whether they actually built the disclosure infrastructure required. Chatbot disclosure is straightforward and most large platforms have implemented it. AI-generated content marking is more complex and compliance is less uniform, particularly for brands using multiple creative tools across multiple channels whose metadata practices differ.
The complaints mechanism that went live this week means that non-compliance is no longer just a regulatory audit risk. It is a consumer complaint risk that can generate enforcement attention at any moment.
The brands that have not yet audited their AI-generated content pipeline and their customer-facing AI deployments should treat today as the last reasonable moment to do that audit before a complaint does it for them.













