If your marketplace platform uses AI anywhere in the customer journey — a shopping assistant, a support chatbot, a recommendation engine — the EU AI Act almost certainly applies to you in some form, even if you've concluded your systems aren't "high-risk." The obligation most marketplaces overlook isn't the one with the scariest name. It's the one that applies to nearly everyone: telling users they're talking to a machine.

The timeline, as it actually stands

The AI Act becomes fully applicable on August 2, 2026. That date matters for two different reasons, and conflating them is where most compliance plans go wrong.

  • Transparency obligations (Article 50) — the rules requiring disclosure when a user is interacting with an AI system — take effect on this date for essentially everyone deploying a chatbot or generative AI system, regardless of risk tier.
  • High-risk system obligations (Annex III) — the heavier compliance burden, including conformity assessments and technical documentation — were set to apply from the same date, but a political agreement reached in May 2026 (the "AI Act Omnibus") defers these specifically for use-based high-risk systems to December 2, 2027. As of this writing, that deferral has cleared both the European Parliament and the Council and is expected to formally enter into force shortly.

In practice: the deadline you can't push off is the transparency requirement. The deadline that gives most marketplaces more runway is the high-risk classification burden — but "more runway" is not "no obligation," and platforms that wait until late 2027 to start will be racing standards bodies and their own engineering backlogs at the same time.

What actually counts as "high-risk" for a marketplace

Most consumer-facing shopping assistants and support chatbots are not automatically high-risk under the Act's Annex III categories, which focus on areas like employment decisions, credit scoring, law enforcement, and critical infrastructure. But marketplaces frequently touch adjacent high-risk territory without realizing it:

  • AI used in hiring or worker management tools embedded in a seller-facing platform
  • Credit or creditworthiness-adjacent scoring built into buy-now-pay-later or seller financing features
  • Any system making decisions that meaningfully affect a person's access to essential services

If none of these apply, your core exposure is the transparency requirement — but that doesn't mean the rest of the Act is irrelevant. The Act also introduced new prohibitions, effective December 2, 2026, on AI systems used to generate non-consensual intimate content, which matters directly for any marketplace with user-generated content or image tools.

The penalties are not theoretical

Violations of the transparency and labeling obligations can carry fines up to €15 million or 3% of global annual turnover, whichever is higher. Violations of the Act's prohibited-practices provisions carry fines up to €35 million or 7% of global turnover. For a marketplace operating at any meaningful scale, these are board-level numbers, not line items.

The compliance-readiness gap in practice: the Digital Omnibus extended simplified compliance treatment to companies with up to 750 employees and €150 million in annual revenue — a meaningfully larger group than the original SME carve-out. If your marketplace falls in that band, check whether you now qualify for simplified documentation requirements before assuming you need the full compliance build-out.

What to actually do before August

  1. Classify every AI touchpoint in your product — not just the obvious chatbot, but recommendation engines, fraud detection, seller scoring, and content moderation systems.
  2. Add clear AI disclosure anywhere a user might reasonably believe they're speaking to a human, ahead of the August deadline.
  3. Document your risk classification reasoning for any system you determine is not high-risk — the Act requires this documentation to be available on request, even for systems you've assessed as lower-risk.
  4. Test behavioral edge cases, not just technical compliance checkboxes. Regulatory documentation demonstrates you assessed the risk; behavioral evaluation demonstrates you actually reduced it — and the two increasingly go hand in hand as enforcement infrastructure matures.

This article is provided for general informational purposes and reflects the regulatory landscape as understood in July 2026. It is not legal advice. The EU AI Act's implementation is actively evolving, and you should consult qualified legal counsel to assess your specific compliance obligations.

Not sure where your AI systems actually stand?

RavenTrak's Compliance Framework Alignment service maps your systems against EU AI Act requirements and identifies gaps before a regulator does.

Schedule a Risk Assessment