AI in Retail and E-commerce
Retailers and e-commerce platforms use AI extensively for product recommendation, dynamic pricing, demand forecasting, fraud detection, customer service automation, and targeted advertising. Consumer protection authorities in the EU, UK, and US are increasingly scrutinizing AI-driven pricing and recommendation systems for fairness and transparency. GDPR and equivalent privacy laws impose constraints on behavioral profiling, while the EU AI Act's requirements for transparency in consumer-facing AI systems are now in force.
Key board-level questions
- 1.Are our AI-driven pricing and recommendation systems compliant with consumer protection and fairness requirements?
- 2.Do we disclose AI interactions to consumers — including chatbots and recommendation engines — in line with applicable transparency obligations?
- 3.How do we manage the data protection and consent requirements that apply to behavioral profiling for advertising and personalization?
- 4.Have we assessed our AI systems for discriminatory outcomes in pricing, service access, or product availability?
Regulatory frameworks
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
EU Data Act
The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.
Colorado AI Act (SB 24-205), repealed
Colorado's SB 24-205, signed in May 2024, would have regulated developers and deployers of high-risk AI. It never took effect: its start date slipped from February 2026 to June 2026. In May 2026 Colorado repealed it and replaced it with SB 26-189, a narrower automated decision-making law effective 1 January 2027.
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
