On 2 August 2026, the transparency obligations in Article 50 of Regulation (EU) 2024/1689 become applicable (AI Act, Article 113). For B2B shops this is not an abstract date from Brussels but a deadline with visible consequences in the storefront: the service chatbot in the customer portal has to disclose before the first exchange that the counterpart is an AI system. Generated images in shop and campaign need machine-readable marking. Voice bots in order intake fall under the same rule. In Germany, the AI Implementation Act supplements the regulation: the Bundestag passed it on 11 June 2026 in the version amended by the digital committee (Deutscher Bundestag), and it cleared the Bundesrat on 10 July 2026 (Bundesrat). The Bundesnetzagentur becomes the central market surveillance authority wherever no other specialist authority has jurisdiction (Bundesnetzagentur). This article sets out which role a shop operator legally holds, which functions in the shop are actually affected, where the widespread worry about AI-generated product copy misreads the wording -- and how the implementation in the template, in the AI inventory and in the privacy and consent structure can be handled predictably. It does not replace legal advice on an individual case.
What actually becomes applicable on 2 August 2026
The AI Act entered into force on 1 August 2024 but becomes applicable in stages (AI Act, Article 113). Since 2 February 2025, the prohibited practices in Article 5 and the AI literacy duty in Article 4 have applied (AI Act, Article 113). Since 2 August 2025, the rules for general-purpose AI models as well as the governance and penalty provisions have been in force (AI Act, Article 113). 2 August 2026 is the third stage: from that date the regulation applies in principle in full -- including the transparency obligations in Article 50 and the high-risk requirements for the use cases listed in Annex III. For the product areas governed by Annex I, the date shifts to 2 August 2027 (Bundesnetzagentur).
For distributors, the classification matters more than the alarm. A B2B shop rarely operates a high-risk system within the meaning of Annex III: neither creditworthiness decisions on natural persons nor biometric procedures belong to the typical feature set of a wholesale shop. That is precisely why Article 50 is the provision that affects almost everyone running a chatbot, an AI advisor or generated media. It imposes no requirements on the model, only on the communication with the human in front of it. And it demands no certification, only a recognisable, documented practice. The Bundesnetzagentur centrally handles market surveillance for the non-harmonised areas and provides an AI service desk with FAQ, contact form and an AI compass for that purpose (Bundesnetzagentur).
| Date | What becomes applicable | Meaning for the B2B shop |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5), AI literacy (Article 4) | Staff training duty already applies today |
| 2 August 2025 | GPAI rules, governance, penalty provisions | Fine framework set, authority structure emerging |
| 2 August 2026 | Article 50 transparency duties, Annex III | Chatbot notice, marking of synthetic content |
| 2 December 2026 | Transition period of the code of practice for systems placed on the market before 2 August 2026 | Window for legacy stocks of generated media |
| 2 August 2027 | Annex I product areas | Usually without direct shop relevance |
Rarely high risk, almost always transparency-bound
Provider or deployer: the role decides the duty
The AI Act distinguishes between providers and deployers. A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in the course of a professional activity. A wholesaler that embeds a ready-made AI service into its customer portal via an interface is therefore normally a deployer, not a provider. This is the decisive fork in practice, because the duties in Article 50 are distributed differently.
Article 50(1) addresses providers: they must design AI systems intended to interact directly with natural persons so that the person concerned is informed that they are interacting with an AI system -- unless this is obvious from the point of view of a reasonably well-informed person (AI Act, Article 50). Article 50(2) requires providers of generative systems to mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. Article 50(4), by contrast, is aimed at deployers: whoever generates or manipulates deepfakes must disclose that the content has been artificially generated or manipulated (AI Act, Article 50). The convenient conclusion is nevertheless wrong: even though paragraph 1 formally binds the provider, the notice appears in your storefront, under your brand, in front of your customers.
Provider
Develops the system or has it developed and places it on the market under its own name. Carries the duties in Article 50(1) and (2), in particular the machine-readable marking of generated outputs.
Deployer
Uses a ready-made AI system under its own professional authority. Carries the disclosure duties in Article 50(3) and (4) -- and has to secure contractually that the provider meets its own obligations.
Change of role
Anyone offering a purchased system under their own name, substantially modifying it or changing its purpose can become a provider under Article 25. With white-label assistants in the customer portal that is not a theoretical question.
The contract is part of compliance
What is actually affected in the shop
Three groups of functions are practically relevant for a B2B shop. The first is the dialogue channel: service chatbot, AI advisor in the product catalogue, assistant features in the customer portal. This is where disclosure of the AI nature before the first exchange applies. The second group is synthetic media: generated product images, application scenes, explainer videos, voiced training content. The third group is voice bots in telephone order intake, which are gaining ground in wholesale. The same timing standard applies to all three: the information must be available clearly and distinguishably at the latest at the time of the first interaction or exposure (AI Act, Article 50).
| Function in the shop | Legal classification | What to do concretely |
|---|---|---|
| Service chatbot in the customer portal | Direct interaction, Article 50(1) | Visible notice before the first message, also exposed to screen readers |
| AI product advisor in the catalogue | Direct interaction, Article 50(1) | Notice in the entry state, no invented staff name |
| Voice bot in order intake | Direct interaction, Article 50(1) | Announcement at the start of the call, documented route to a human |
| Generated product and scene images | Synthetic content, Article 50(2) | Machine-readable marking by the provider, preserved in the media pipeline |
| Realistic-looking people or places | Deepfake, Article 50(4) | Additional visible disclosure on the content itself |
| Translated category texts | Text without public interest | Usually no disclosure duty, but quality assurance |
The European Commission's code of practice on the transparency of AI-generated content was published on 10 June 2026 and is open for signature (European Commission). It is voluntary and does not replace the regulation, but it specifies what can count as an adequate implementation. For providers it recommends combining at least two layers of machine-readable marking where necessary -- for example metadata and watermarks or other technical measures (European Commission). For deployers it describes the design, placement and presentation of the visible notice, including an EU label or equivalent labels and an audio disclaimer where visual labelling is not feasible (European Commission).
The deepfake concept is broader than many assume
The key distinction: AI-generated product copy
The most frequent question in project meetings is: do we now have to put a notice under every AI-generated article description? The wording argues against it. The disclosure duty for text in Article 50(4) explicitly attaches to text published for the purpose of informing the public on matters of public interest (AI Act, Article 50). It targets the journalistic space, not the product catalogue. A description of a hydraulic coupling does not inform the public about a matter of public interest -- it describes goods in commercial dealings.
A second limitation follows in the same paragraph: the duty does not apply where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication (AI Act, Article 50). Anyone who checks, documents and signs off generated texts before release therefore stands on firm ground even in borderline journalistic cases. This distinction is a relief -- but it is not a free pass.
- The ban on misleading claims stays untouched. A generated description that invents technical properties is vulnerable under competition law, regardless of whether an AI notice sits next to it.
- Product data quality becomes a liability question. Dimensions, materials, standards references and safety notes are contractually relevant in technical trade. Generated phrasing must not overwrite the data source.
- Sector-specific labelling law continues to apply. Chemicals, food, medical technology and electrical engineering bring their own mandatory information that no language model should produce.
- Editorial responsibility needs a name. Whoever approves should be recorded in the workflow -- which is at the same time the documentation Article 50(4) relies on.
- Magazine articles differ from article copy. A guide on regulatory topics in the shop magazine may well have public relevance.
Data quality beats labelling
Implementation in the storefront: notice, metadata, privacy texts
Article 50(5) sets out how the information has to look: clear and distinguishable, at the latest at the time of the first interaction or exposure, and in conformity with the applicable accessibility requirements (AI Act, Article 50). For implementation that means three things at once -- visible, placed up front, and readable by assistive technology. A notice that only appears after the third message, or that sits as a grey footnote under the input field, does not serve the purpose. In the Shopware implementation this is a manageable template task if it is considered before rollout.
- Notice in the entry state of the chat widget. Before the first message can be sent, it says in substance: you are writing with an AI assistant. The text stays reachable in the conversation, not only as a one-off overlay.
- Accessible markup. The dialogue gets a clear role and an accessible name carrying the AI notice, so screen readers announce it on focus change. Colour or icon cues alone are not enough.
- No simulated humanity. No invented staff name, no portrait photo of a non-existent person, no phrasing suggesting personal presence. A neutral assistant name is permitted and more honest.
- Name the handover to a human. The route out of the bot -- callback, ticket, sales contact -- belongs visibly in the dialogue. In B2B that is a service advantage anyway.
- Extend privacy policy and usage notes. Purpose, category of AI system used, processing location, retention of conversations and contact person belong in the information duties under Articles 13 and 14 GDPR.
- Preserve provenance metadata on images. Where generated media arrive with provenance metadata, the image pipeline, resizing and CDN must not strip it. That is a technical check in the media process, not an editorial topic.
The information shall be provided to the natural person concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure -- and it shall conform to the applicable accessibility requirements.
The reference to accessibility is not decoration. It links the labelling duty directly to requirements that already apply in the shop -- focus order, contrast, operability without a mouse, understandable labels. Anyone marking up the chat notice properly is working at the same place where the accessibility requirements for e-commerce apply. The transition period until 2 December 2026 in the code of practice concerns solely systems placed on the market before 2 August 2026 (European Commission) -- it is a window for legacy stock, not an extra reprieve for new projects.
The AI inventory as compulsory groundwork
Before any technical implementation comes an unspectacular question: where exactly is AI in this shop? The answer regularly turns out longer than expected, because many functions were bought as a product feature and never regarded as an AI system. Search relevance, recommendation logic, basket suggestions, automatic translations, image cutouts, fraud detection at checkout: each of these can be an AI system within the meaning of the regulation or not -- and that can only be decided once the list exists. According to Bitkom, 41 percent of companies with 20 or more employees already use AI, with another 48 percent planning or discussing it (Bitkom, survey of 604 companies, March 2026). The probability that a grown shop stack is affected is correspondingly high.
- Onsite search and relevance tuning -- provider, model type, training data from your own catalogue, internal owner
- Recommendations and cross-selling -- purpose, data basis, whether personal data is processed, legal basis
- Service chatbot and AI advisor -- role as deployer, notice text in the template, escalation route to a human
- Voice bot in order intake -- announcement text, recording, retention period, consent situation
- Translations for international shops -- approval process, terminology, responsibility for the final wording
- Image and video generation -- provider, machine-readable marking, preservation of metadata in the media process
- Text generation for catalogue and magazine -- editorial control, named approval, public-interest boundary
- Fraud detection and risk checks at checkout -- purpose, effects on the customer, review for high-risk relevance
Four entries belong in the table for every line: provider, purpose, data flow and the responsible person in-house. This inventory is the basis for everything else -- for the notices in the template, for the privacy policy, for training planning and for the question which contract needs sharpening. It is also the document needed first when the market surveillance authority asks. In grown system landscapes the survey is more laborious than it sounds, because AI functions often sit deep in search profiles and catalogue pipelines; how strongly such functions depend on the article master becomes clear in onsite search across part numbers. Anyone considering an architectural change anyway should tie the inventory to the decision for or against headless and composable commerce -- the question of which service answers where is being reopened there in any case.
The inventory is not a one-off product
AI literacy under Article 4 and the documentation behind it
Article 4 of the AI Act has applied since 2 February 2025 and is often overlooked in the debate about the August deadline (AI Act, Article 113). Providers and deployers shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf -- taking into account technical knowledge, experience, education and training and the context of use (AI Act, Article 4). The provision names no format and no number of hours. It demands adequacy, and adequacy can only be evidenced if something is documented.
Who is trained
Customer service and inside sales, because they work with bot conversations. Marketing and catalogue editing, because they create content. IT and the shop team, because they integrate systems. Management, because it carries responsibility.
What the content should be
Understanding of the provider versus deployer role, the limits of the systems, handling faulty outputs, the labelling rules in your own shop, data protection and the route to a human on escalation.
How it is evidenced
Attendance lists, date, content overview, version of the internal policy. Complemented by a short written usage rule defining which systems are approved for which purposes.
The documentation is not an end in itself. It is the difference between an organisation that answers an enquiry in two hours and one that needs two weeks and external help. A lean bundle is workable: the AI inventory, an internal usage policy, the training records, the contractual annexes of the services in use and a change log. Anyone already running structured shop maintenance and operations attaches these items to an existing rhythm instead of building a parallel structure.
Fine ranges and market surveillance in perspective
Article 99 of the AI Act grades penalties by the severity of the infringement. For breaches of the transparency obligations of providers and deployers, the regulation provides for fines of up to 15 million euros or up to 3 percent of total worldwide annual turnover of the preceding financial year, whichever is higher (AI Act, Article 99). For prohibited practices under Article 5 the range is 35 million euros or 7 percent, for incorrect, incomplete or misleading information to authorities 7.5 million euros or 1 percent (AI Act, Article 99). For small and medium-sized enterprises including start-ups, the lower of the two values applies (AI Act, Article 99).
| Infringement | Range under Article 99 | Shop relevance |
|---|---|---|
| Prohibited practices (Article 5) | EUR 35m or 7 percent | rarely relevant in distribution |
| Transparency obligations (Article 50) | EUR 15m or 3 percent | chatbot notice, synthetic media |
| Incorrect information to authorities | EUR 7.5m or 1 percent | replies in a surveillance procedure |
| Assessment | effective, proportionate, dissuasive | severity, size, intent, cooperation count |
| SMEs and start-ups | the lower value in each case | noticeably relieves mid-market firms |
These figures are upper limits, not standard amounts. The regulation requires penalties that are effective, proportionate and dissuasive and names as assessment criteria, among others, the gravity and duration of the infringement, the size of the operator, intent or negligence and cooperation with the authorities (AI Act, Article 99). For a mid-market wholesaler retrofitting a missing chatbot notice, an extreme figure is not a realistic scenario. The actual incentive lies elsewhere: under the AI Implementation Act, the Bundesnetzagentur also acts as the central complaints office for reports of alleged infringements (Bundesnetzagentur). Procedures therefore start more often through third-party reports than through routine inspections -- a pattern familiar from other regulatory fields.
The German structure is in place
Practice in B2B: portal, part-number search, quote drafts
In B2B shops, AI functions are distributed differently than in consumer business. They rarely sit in the campaign and often in the process: in the customer portal, in search across part numbers and factory designations, in preparing quotes. That is exactly why a function-by-function view beats the blanket question of whether AI is in use. Six typical constellations with a clear assignment.
Chatbot in the customer portal
Direct interaction. Notice before the first exchange, even if only logged-in business customers have access. The closed area changes nothing about the duty.
AI search across part numbers
Usually no disclosure duty, because no dialogue and no synthetic content arises. It still belongs in the inventory, because data flow and provider have to be documented.
Automated quote drafts
The draft is an internal work product. As soon as it goes to the customer without a technical check, editorial control is missing -- and liability for the content stays with the sender.
Generated application images
Synthetic content with a marking duty on the provider. If the image looks like a real photograph of your own operation, visible disclosure is added.
Voice bot in order intake
An announcement at the start of the call rather than a note in the small print. Also to be clarified: recording, retention and the documented route to a human.
Translated country catalogues
Machine translation produces text but usually no public-interest relevance within the meaning of Article 50(4). Technical approval remains sensible for liability reasons.
It is striking how often the answer to the labelling question depends on process design rather than technology. A quote draft that inside sales reviews, completes and approves is a different matter from an automatically dispatched price quotation -- even though the same function sits behind it. The same logic applies to calculations running in the background: anyone calculating shipping costs and freight surcharges in a B2B shop should know whether and where a learning procedure is involved. And anyone expanding their customer portal as a self-service channel decides on a labelling question with every new assistant.
The closed area offers no exemption
How to work through the deadline predictably
The task splits into three blocks that can be kept apart cleanly: record, implement, document. The first block is analysis and can largely be done without development. The second block is frontend and template work in the shop, plus the media pipeline. The third block is organisation -- policy, training, records. In that order the effort stays manageable, because every implementation builds on a decision taken beforehand. The reverse creates the expensive loops: anyone who first builds notices and then compiles the inventory rewrites the texts twice.
AI inventory and compliance check
Survey of all AI functions in the existing shop stack with provider, purpose, data flow and owner, plus the provider-versus-deployer role clarification per function and an assessment of the contractual situation.
Technical implementation in the storefront
Notices in the chat widget and in assistant features, accessible markup, adjustment of the privacy and consent structure, review of the media pipeline for preservation of provenance metadata.
Documentation and operations
Internal usage policy, training records under Article 4, a checkpoint at every acceptance of new functions and a fixed review interval so the inventory grows with the shop.
For a mid-sized B2B shop, a project scope of a few weeks is realistic if inventory and implementation run in parallel and responsibilities are clarified early (project experience). The larger share of the effort typically lies not in the code but in clarifying which function belongs to whom (project experience). That is exactly where a structured survey starts: it turns a diffuse regulatory question into a list with owners and dates. After that, implementation in the template is routine.
The entry point is a list, not a legal opinion
Sources and studies