Skip to content
GDPR-compliant B2B shops
Law & compliance

AI Act Labelling Duties for B2B Shops from August 2026

From 2 August 2026 Article 50 of the AI Act applies: what B2B shops must label for chatbots, generated images and product copy -- and what they need not.

14 min read KI-VerordnungComplianceB2B E-CommerceShopwareKundenservice

On 2 August 2026, the transparency obligations in Article 50 of Regulation (EU) 2024/1689 become applicable (AI Act, Article 113). For B2B shops this is not an abstract date from Brussels but a deadline with visible consequences in the storefront: the service chatbot in the customer portal has to disclose before the first exchange that the counterpart is an AI system. Generated images in shop and campaign need machine-readable marking. Voice bots in order intake fall under the same rule. In Germany, the AI Implementation Act supplements the regulation: the Bundestag passed it on 11 June 2026 in the version amended by the digital committee (Deutscher Bundestag), and it cleared the Bundesrat on 10 July 2026 (Bundesrat). The Bundesnetzagentur becomes the central market surveillance authority wherever no other specialist authority has jurisdiction (Bundesnetzagentur). This article sets out which role a shop operator legally holds, which functions in the shop are actually affected, where the widespread worry about AI-generated product copy misreads the wording -- and how the implementation in the template, in the AI inventory and in the privacy and consent structure can be handled predictably. It does not replace legal advice on an individual case.

AI labelling duties for B2B shops from 2 August 2026Article 50 from 2 August 2026Bundesnetzagentur as supervisorup to EUR 15m or 3 percentApplication stages of the AI ActKey date2 Feb 20252 Aug 20252 Aug 20262 Dec 2026AI literacy(Article 4)penalties andGPAI rulesArticle 50 becomesapplicabletransition forlegacy systemsWhat needs labelling in the shopChatbot and AI advisorSynthetic mediaProduct and category textdisclosure requiredmarking and disclosurenot automatically coverednotice before the first exchangeArticle 50(1)voice bots includedmachine-readable by providerdisclosure for deepfakesArticle 50(2) and 50(4)no matter of public interestArticle 50(4), second sentencemisleading claims still barred41 %use AIof companies with 20 or more staff(Bitkom)Fine ranges under the AI Actprohibited practices (Article 5)EUR 35m or 7 %transparency (Article 50)EUR 15m or 3 %incorrect information to authoritiesEUR 7.5m or 1 %whichever is higher, the lower value for SMEs(AI Act, Article 99)Market surveillanceBundesnetzagenturcentral complaints officeAI market surveillance chamberat least one AI sandboxAI service desk and compass(Bundesnetzagentur)

What actually becomes applicable on 2 August 2026

The AI Act entered into force on 1 August 2024 but becomes applicable in stages (AI Act, Article 113). Since 2 February 2025, the prohibited practices in Article 5 and the AI literacy duty in Article 4 have applied (AI Act, Article 113). Since 2 August 2025, the rules for general-purpose AI models as well as the governance and penalty provisions have been in force (AI Act, Article 113). 2 August 2026 is the third stage: from that date the regulation applies in principle in full -- including the transparency obligations in Article 50 and the high-risk requirements for the use cases listed in Annex III. For the product areas governed by Annex I, the date shifts to 2 August 2027 (Bundesnetzagentur).

For distributors, the classification matters more than the alarm. A B2B shop rarely operates a high-risk system within the meaning of Annex III: neither creditworthiness decisions on natural persons nor biometric procedures belong to the typical feature set of a wholesale shop. That is precisely why Article 50 is the provision that affects almost everyone running a chatbot, an AI advisor or generated media. It imposes no requirements on the model, only on the communication with the human in front of it. And it demands no certification, only a recognisable, documented practice. The Bundesnetzagentur centrally handles market surveillance for the non-harmonised areas and provides an AI service desk with FAQ, contact form and an AI compass for that purpose (Bundesnetzagentur).

DateWhat becomes applicableMeaning for the B2B shop
2 February 2025Prohibited practices (Article 5), AI literacy (Article 4)Staff training duty already applies today
2 August 2025GPAI rules, governance, penalty provisionsFine framework set, authority structure emerging
2 August 2026Article 50 transparency duties, Annex IIIChatbot notice, marking of synthetic content
2 December 2026Transition period of the code of practice for systems placed on the market before 2 August 2026Window for legacy stocks of generated media
2 August 2027Annex I product areasUsually without direct shop relevance

Rarely high risk, almost always transparency-bound

The common worry that a shop turns into a high-risk system misses the point in most cases. The real work arises at a far less spectacular place: whether a customer can tell that they are talking to a machine, and whether a generated image is recognisable as such. That can be solved in the template -- not in the model.

Provider or deployer: the role decides the duty

The AI Act distinguishes between providers and deployers. A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in the course of a professional activity. A wholesaler that embeds a ready-made AI service into its customer portal via an interface is therefore normally a deployer, not a provider. This is the decisive fork in practice, because the duties in Article 50 are distributed differently.

Article 50(1) addresses providers: they must design AI systems intended to interact directly with natural persons so that the person concerned is informed that they are interacting with an AI system -- unless this is obvious from the point of view of a reasonably well-informed person (AI Act, Article 50). Article 50(2) requires providers of generative systems to mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. Article 50(4), by contrast, is aimed at deployers: whoever generates or manipulates deepfakes must disclose that the content has been artificially generated or manipulated (AI Act, Article 50). The convenient conclusion is nevertheless wrong: even though paragraph 1 formally binds the provider, the notice appears in your storefront, under your brand, in front of your customers.

Provider

Develops the system or has it developed and places it on the market under its own name. Carries the duties in Article 50(1) and (2), in particular the machine-readable marking of generated outputs.

Deployer

Uses a ready-made AI system under its own professional authority. Carries the disclosure duties in Article 50(3) and (4) -- and has to secure contractually that the provider meets its own obligations.

Change of role

Anyone offering a purchased system under their own name, substantially modifying it or changing its purpose can become a provider under Article 25. With white-label assistants in the customer portal that is not a theoretical question.

The contract is part of compliance

As a deployer you cannot produce the machine-readable marking yourself -- it originates in the provider's system. What the contract says therefore matters: is marking applied, by which method, and does the marking survive further processing in the shop? These questions belong in the statement of work, not in a later crisis meeting.

What is actually affected in the shop

Three groups of functions are practically relevant for a B2B shop. The first is the dialogue channel: service chatbot, AI advisor in the product catalogue, assistant features in the customer portal. This is where disclosure of the AI nature before the first exchange applies. The second group is synthetic media: generated product images, application scenes, explainer videos, voiced training content. The third group is voice bots in telephone order intake, which are gaining ground in wholesale. The same timing standard applies to all three: the information must be available clearly and distinguishably at the latest at the time of the first interaction or exposure (AI Act, Article 50).

Function in the shopLegal classificationWhat to do concretely
Service chatbot in the customer portalDirect interaction, Article 50(1)Visible notice before the first message, also exposed to screen readers
AI product advisor in the catalogueDirect interaction, Article 50(1)Notice in the entry state, no invented staff name
Voice bot in order intakeDirect interaction, Article 50(1)Announcement at the start of the call, documented route to a human
Generated product and scene imagesSynthetic content, Article 50(2)Machine-readable marking by the provider, preserved in the media pipeline
Realistic-looking people or placesDeepfake, Article 50(4)Additional visible disclosure on the content itself
Translated category textsText without public interestUsually no disclosure duty, but quality assurance

The European Commission's code of practice on the transparency of AI-generated content was published on 10 June 2026 and is open for signature (European Commission). It is voluntary and does not replace the regulation, but it specifies what can count as an adequate implementation. For providers it recommends combining at least two layers of machine-readable marking where necessary -- for example metadata and watermarks or other technical measures (European Commission). For deployers it describes the design, placement and presentation of the visible notice, including an EU label or equivalent labels and an audio disclaimer where visual labelling is not feasible (European Commission).

The deepfake concept is broader than many assume

A deepfake within the meaning of the regulation is not limited to faked politician videos. It covers image, audio or video content resembling existing persons, objects, places or events that would falsely appear authentic. A photorealistic warehouse image suggesting your own site, or a synthetic speaker that sounds like an employee, can fall under it. For artistic, satirical or fictional works, disclosure is limited to indicating the existence of such content in an appropriate manner (AI Act, Article 50).

The key distinction: AI-generated product copy

The most frequent question in project meetings is: do we now have to put a notice under every AI-generated article description? The wording argues against it. The disclosure duty for text in Article 50(4) explicitly attaches to text published for the purpose of informing the public on matters of public interest (AI Act, Article 50). It targets the journalistic space, not the product catalogue. A description of a hydraulic coupling does not inform the public about a matter of public interest -- it describes goods in commercial dealings.

A second limitation follows in the same paragraph: the duty does not apply where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication (AI Act, Article 50). Anyone who checks, documents and signs off generated texts before release therefore stands on firm ground even in borderline journalistic cases. This distinction is a relief -- but it is not a free pass.

  • The ban on misleading claims stays untouched. A generated description that invents technical properties is vulnerable under competition law, regardless of whether an AI notice sits next to it.
  • Product data quality becomes a liability question. Dimensions, materials, standards references and safety notes are contractually relevant in technical trade. Generated phrasing must not overwrite the data source.
  • Sector-specific labelling law continues to apply. Chemicals, food, medical technology and electrical engineering bring their own mandatory information that no language model should produce.
  • Editorial responsibility needs a name. Whoever approves should be recorded in the workflow -- which is at the same time the documentation Article 50(4) relies on.
  • Magazine articles differ from article copy. A guide on regulatory topics in the shop magazine may well have public relevance.

Data quality beats labelling

Feeding generated texts from a cleanly maintained article master defuses much of the labelling issue almost in passing: the statements are correct, the source is traceable, the approval documented. How strongly product data quality and PIM processes shape everything downstream becomes particularly clear here.

Implementation in the storefront: notice, metadata, privacy texts

Article 50(5) sets out how the information has to look: clear and distinguishable, at the latest at the time of the first interaction or exposure, and in conformity with the applicable accessibility requirements (AI Act, Article 50). For implementation that means three things at once -- visible, placed up front, and readable by assistive technology. A notice that only appears after the third message, or that sits as a grey footnote under the input field, does not serve the purpose. In the Shopware implementation this is a manageable template task if it is considered before rollout.

  1. Notice in the entry state of the chat widget. Before the first message can be sent, it says in substance: you are writing with an AI assistant. The text stays reachable in the conversation, not only as a one-off overlay.
  2. Accessible markup. The dialogue gets a clear role and an accessible name carrying the AI notice, so screen readers announce it on focus change. Colour or icon cues alone are not enough.
  3. No simulated humanity. No invented staff name, no portrait photo of a non-existent person, no phrasing suggesting personal presence. A neutral assistant name is permitted and more honest.
  4. Name the handover to a human. The route out of the bot -- callback, ticket, sales contact -- belongs visibly in the dialogue. In B2B that is a service advantage anyway.
  5. Extend privacy policy and usage notes. Purpose, category of AI system used, processing location, retention of conversations and contact person belong in the information duties under Articles 13 and 14 GDPR.
  6. Preserve provenance metadata on images. Where generated media arrive with provenance metadata, the image pipeline, resizing and CDN must not strip it. That is a technical check in the media process, not an editorial topic.

The information shall be provided to the natural person concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure -- and it shall conform to the applicable accessibility requirements.

In substance, Article 50(5) of Regulation (EU) 2024/1689

The reference to accessibility is not decoration. It links the labelling duty directly to requirements that already apply in the shop -- focus order, contrast, operability without a mouse, understandable labels. Anyone marking up the chat notice properly is working at the same place where the accessibility requirements for e-commerce apply. The transition period until 2 December 2026 in the code of practice concerns solely systems placed on the market before 2 August 2026 (European Commission) -- it is a window for legacy stock, not an extra reprieve for new projects.

The AI inventory as compulsory groundwork

Before any technical implementation comes an unspectacular question: where exactly is AI in this shop? The answer regularly turns out longer than expected, because many functions were bought as a product feature and never regarded as an AI system. Search relevance, recommendation logic, basket suggestions, automatic translations, image cutouts, fraud detection at checkout: each of these can be an AI system within the meaning of the regulation or not -- and that can only be decided once the list exists. According to Bitkom, 41 percent of companies with 20 or more employees already use AI, with another 48 percent planning or discussing it (Bitkom, survey of 604 companies, March 2026). The probability that a grown shop stack is affected is correspondingly high.

  • Onsite search and relevance tuning -- provider, model type, training data from your own catalogue, internal owner
  • Recommendations and cross-selling -- purpose, data basis, whether personal data is processed, legal basis
  • Service chatbot and AI advisor -- role as deployer, notice text in the template, escalation route to a human
  • Voice bot in order intake -- announcement text, recording, retention period, consent situation
  • Translations for international shops -- approval process, terminology, responsibility for the final wording
  • Image and video generation -- provider, machine-readable marking, preservation of metadata in the media process
  • Text generation for catalogue and magazine -- editorial control, named approval, public-interest boundary
  • Fraud detection and risk checks at checkout -- purpose, effects on the customer, review for high-risk relevance

Four entries belong in the table for every line: provider, purpose, data flow and the responsible person in-house. This inventory is the basis for everything else -- for the notices in the template, for the privacy policy, for training planning and for the question which contract needs sharpening. It is also the document needed first when the market surveillance authority asks. In grown system landscapes the survey is more laborious than it sounds, because AI functions often sit deep in search profiles and catalogue pipelines; how strongly such functions depend on the article master becomes clear in onsite search across part numbers. Anyone considering an architectural change anyway should tie the inventory to the decision for or against headless and composable commerce -- the question of which service answers where is being reopened there in any case.

The inventory is not a one-off product

Shop stacks change with every plugin update and every new module. A fixed checkpoint is therefore sensible: every new function that generates content, issues recommendations or talks to customers is entered into the inventory at acceptance. That costs minutes per release and saves reconstructing everything from memory later.

AI literacy under Article 4 and the documentation behind it

Article 4 of the AI Act has applied since 2 February 2025 and is often overlooked in the debate about the August deadline (AI Act, Article 113). Providers and deployers shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf -- taking into account technical knowledge, experience, education and training and the context of use (AI Act, Article 4). The provision names no format and no number of hours. It demands adequacy, and adequacy can only be evidenced if something is documented.

Who is trained

Customer service and inside sales, because they work with bot conversations. Marketing and catalogue editing, because they create content. IT and the shop team, because they integrate systems. Management, because it carries responsibility.

What the content should be

Understanding of the provider versus deployer role, the limits of the systems, handling faulty outputs, the labelling rules in your own shop, data protection and the route to a human on escalation.

How it is evidenced

Attendance lists, date, content overview, version of the internal policy. Complemented by a short written usage rule defining which systems are approved for which purposes.

The documentation is not an end in itself. It is the difference between an organisation that answers an enquiry in two hours and one that needs two weeks and external help. A lean bundle is workable: the AI inventory, an internal usage policy, the training records, the contractual annexes of the services in use and a change log. Anyone already running structured shop maintenance and operations attaches these items to an existing rhythm instead of building a parallel structure.

Fine ranges and market surveillance in perspective

Article 99 of the AI Act grades penalties by the severity of the infringement. For breaches of the transparency obligations of providers and deployers, the regulation provides for fines of up to 15 million euros or up to 3 percent of total worldwide annual turnover of the preceding financial year, whichever is higher (AI Act, Article 99). For prohibited practices under Article 5 the range is 35 million euros or 7 percent, for incorrect, incomplete or misleading information to authorities 7.5 million euros or 1 percent (AI Act, Article 99). For small and medium-sized enterprises including start-ups, the lower of the two values applies (AI Act, Article 99).

InfringementRange under Article 99Shop relevance
Prohibited practices (Article 5)EUR 35m or 7 percentrarely relevant in distribution
Transparency obligations (Article 50)EUR 15m or 3 percentchatbot notice, synthetic media
Incorrect information to authoritiesEUR 7.5m or 1 percentreplies in a surveillance procedure
Assessmenteffective, proportionate, dissuasiveseverity, size, intent, cooperation count
SMEs and start-upsthe lower value in each casenoticeably relieves mid-market firms

These figures are upper limits, not standard amounts. The regulation requires penalties that are effective, proportionate and dissuasive and names as assessment criteria, among others, the gravity and duration of the infringement, the size of the operator, intent or negligence and cooperation with the authorities (AI Act, Article 99). For a mid-market wholesaler retrofitting a missing chatbot notice, an extreme figure is not a realistic scenario. The actual incentive lies elsewhere: under the AI Implementation Act, the Bundesnetzagentur also acts as the central complaints office for reports of alleged infringements (Bundesnetzagentur). Procedures therefore start more often through third-party reports than through routine inspections -- a pattern familiar from other regulatory fields.

The German structure is in place

The AI Implementation Act sets up an AI market surveillance chamber inside the Bundesnetzagentur, bundles expertise in a coordination and competence centre and requires at least one AI regulatory sandbox in which small and medium-sized enterprises and start-ups in particular can test new applications under supervision (Bundesnetzagentur). Evaluations after 18 months and after three years are also foreseen (Deutscher Bundestag). Anyone who works through regulation systematically already knows the approach from NIS2 and IT security duties.

Practice in B2B: portal, part-number search, quote drafts

In B2B shops, AI functions are distributed differently than in consumer business. They rarely sit in the campaign and often in the process: in the customer portal, in search across part numbers and factory designations, in preparing quotes. That is exactly why a function-by-function view beats the blanket question of whether AI is in use. Six typical constellations with a clear assignment.

Chatbot in the customer portal

Direct interaction. Notice before the first exchange, even if only logged-in business customers have access. The closed area changes nothing about the duty.

AI search across part numbers

Usually no disclosure duty, because no dialogue and no synthetic content arises. It still belongs in the inventory, because data flow and provider have to be documented.

Automated quote drafts

The draft is an internal work product. As soon as it goes to the customer without a technical check, editorial control is missing -- and liability for the content stays with the sender.

Generated application images

Synthetic content with a marking duty on the provider. If the image looks like a real photograph of your own operation, visible disclosure is added.

Voice bot in order intake

An announcement at the start of the call rather than a note in the small print. Also to be clarified: recording, retention and the documented route to a human.

Translated country catalogues

Machine translation produces text but usually no public-interest relevance within the meaning of Article 50(4). Technical approval remains sensible for liability reasons.

It is striking how often the answer to the labelling question depends on process design rather than technology. A quote draft that inside sales reviews, completes and approves is a different matter from an automatically dispatched price quotation -- even though the same function sits behind it. The same logic applies to calculations running in the background: anyone calculating shipping costs and freight surcharges in a B2B shop should know whether and where a learning procedure is involved. And anyone expanding their customer portal as a self-service channel decides on a labelling question with every new assistant.

The closed area offers no exemption

A common misconception holds that Article 50 does not apply in the logged-in business area because no consumers are present. The provision, however, refers to natural persons interacting with the system -- and in B2B that is the buyer, the planner or the technician at the screen. The duty attaches to the human in front of the system, not to the contractual relationship behind it.

How to work through the deadline predictably

The task splits into three blocks that can be kept apart cleanly: record, implement, document. The first block is analysis and can largely be done without development. The second block is frontend and template work in the shop, plus the media pipeline. The third block is organisation -- policy, training, records. In that order the effort stays manageable, because every implementation builds on a decision taken beforehand. The reverse creates the expensive loops: anyone who first builds notices and then compiles the inventory rewrites the texts twice.

AI inventory and compliance check

Survey of all AI functions in the existing shop stack with provider, purpose, data flow and owner, plus the provider-versus-deployer role clarification per function and an assessment of the contractual situation.

Technical implementation in the storefront

Notices in the chat widget and in assistant features, accessible markup, adjustment of the privacy and consent structure, review of the media pipeline for preservation of provenance metadata.

Documentation and operations

Internal usage policy, training records under Article 4, a checkpoint at every acceptance of new functions and a fixed review interval so the inventory grows with the shop.

For a mid-sized B2B shop, a project scope of a few weeks is realistic if inventory and implementation run in parallel and responsibilities are clarified early (project experience). The larger share of the effort typically lies not in the code but in clarifying which function belongs to whom (project experience). That is exactly where a structured survey starts: it turns a diffuse regulatory question into a list with owners and dates. After that, implementation in the template is routine.

The entry point is a list, not a legal opinion

If you cannot say today how many AI functions run in your shop, that is the starting point -- not the problem. We survey the existing stack, assign every function to a role and a duty and derive a workable implementation plan for storefront, consent structure and documentation. This can start as a scoped B2B e-commerce consulting engagement or be booked directly as a survey. The legal assessment of the individual case belongs alongside it in the hands of qualified legal counsel.

Sources and studies

This article is based on data from: Regulation (EU) 2024/1689 on artificial intelligence (AI Act), in particular Article 4 (AI literacy), Article 25 (responsibilities along the value chain), Article 50(1) to (7) (transparency obligations), Article 99 (penalties) and Article 113 (entry into application), published via EUR-Lex; European Commission -- Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026, including the transitional arrangement until 2 December 2026 for systems placed on the market before 2 August 2026; Bundesnetzagentur -- market surveillance for artificial intelligence, AI service desk and AI compass; Deutscher Bundestag -- Act implementing the Regulation on Artificial Intelligence (AI Implementation Act), decision of 11 June 2026; Bundesrat -- 1067th session on 10 July 2026; German Federal Government -- implementation of the AI Act in Germany; Bitkom -- press release on the digitalisation of the economy dated 11 March 2026 (telephone survey of 604 companies with 20 or more employees); General Data Protection Regulation (Articles 13 and 14). Legal status July 2026. The article reflects the state of the discussion and does not replace legal advice on an individual case.

Related Articles