Your Chatbot Label Isn’t Legally Your Problem. Your Virtual Try-On Could Be.

VisioncarePro by

On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act became applicable. Every checklist written for e-commerce since has said roughly the same two things: label your chatbot, and mark your AI-generated images.

Both of those duties are real. Neither of them is yours.

Article 50 contains four duties and splits them between two roles. Two fall on the provider — whoever built the system and put it on the market. Two fall on the deployer — the shop using it. An eyewear store running off-the-shelf apps is almost always the deployer, and the two duties that genuinely land on a deployer are the two that never make the top of anyone’s list. One of them points straight at a feature most eyewear stores now run.

Here is the split, what it means for a store selling glasses, and the one number in the standard advice that is wrong for almost everyone reading this.

The split nobody writes down

Article 50 divides like this:

  • Article 50(1) — tell people they are talking to an AI. A duty on providers, who must design the system so people are informed, unless it is obvious to a person who is reasonably well-informed, observant and circumspect.
  • Article 50(2) — mark synthetic output in a machine-readable format. A duty on providers of the generating system. It carves out assistive editing functions and alterations that do not substantially change the input.
  • Article 50(3) — tell people when a system recognises their emotions or categorises them biometrically. A duty on deployers.
  • Article 50(4) — disclose deep fakes. A duty on deployers.

Which side you sit on is decided by two definitions. A provider, under Article 3(3), develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. A deployer, under Article 3(4), is anyone using an AI system under its own authority in a professional capacity.

Install a chatbot from the app store and you did not develop it and did not have it developed. You are the deployer. The labelling duty in 50(1) belongs to the company that built it.

One honest caveat, because this is the part that is genuinely arguable: if you strip the vendor’s branding and present the assistant wholly as your own, someone could contend you have put a system into service under your own trademark. The Act does not settle that for an off-the-shelf app, and no guidance found to date settles it either. Note also what does not rescue you: Article 25, the provision that turns a distributor or deployer into a provider when they put their name on a system, is limited to high-risk AI systems. It does not reach Article 50 systems in either direction.

So treat the boundary as unsettled, and read the rest of this on the assumption you are a deployer — because for the two duties that follow, you certainly are.

The first duty that is actually yours: virtual try-on

Article 50(3) requires a deployer of an emotion recognition system or a biometric categorisation system to inform the people exposed to it, and to process their personal data under the GDPR.

So: is a virtual try-on a biometric categorisation system? The definition, at Article 3(40), is narrower than it looks:

“biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.”

That carve-out is the whole question, and the Act’s own recital 16 answers it with an example that could have been written about eyewear:

“Filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself.”

A try-on that maps a face in order to show a frame on it, and does nothing else with the result, sits outside the definition. That is the good news, and it is better founded than the usual reassurance, because it comes from the instrument itself rather than from a consultant’s summary.

The bad news is that the carve-out has conditions, and they are conditions a merchant can break without noticing. Recital 16 requires the feature to be purely ancillary and intrinsically linked to the principal service, unable to function independently of it, and not used to circumvent the rules. Three ordinary commercial decisions step outside that:

  • You keep the category. The try-on works out a face shape, and that value is written to the customer record and used to segment an email campaign. The categorisation now has a life beyond the preview.
  • You unbundle it. A standalone “find your face shape” quiz that runs without any frame being displayed is no longer intrinsically linked to selling a product.
  • You pass it on. The categorisation is shared with an analytics or advertising vendor.

Do any of those and you are deploying a biometric categorisation system, and Article 50(3) is your duty, not your vendor’s: you must inform the people exposed to it. It is a notice, not a consent form — but it is yours to write.

Two neighbouring points. Emotion recognition is treated the same way by 50(3) and has no ancillary carve-out; if any “smart mirror” or engagement-analytics feature infers how a shopper feels, that is squarely in scope. And all of this sits on top of the GDPR question, which is the sharper risk for most stores and which moved in the United States this summer in a way that removed an argument eyewear sellers had been leaning on — see Your Virtual Try-On Just Lost Its Legal Shield.

The second duty that is actually yours: the model in the photograph

Article 50(4) requires deployers of a system that generates or manipulates a deep fake to disclose that the content is artificially generated or manipulated. Again the definition does the work. Article 3(60):

“deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.”

The operative words are resembles existing persons. A wholly synthetic model who resembles nobody in particular is a weaker case for 50(4) than most coverage suggests. What is clearly in scope is narrower and more specific:

  • An AI-rendered version of a real ambassador, influencer or staff member wearing frames they never wore.
  • A “see this frame on someone like you” feature built from a customer’s own uploaded photograph.
  • A real product photograph manipulated so that the scene it depicts never happened.

This is also the point where Europe and the United States diverge, and the American rule is the broader one — New York’s disclosure law does not wait for a real person to be depicted. If you sell on both sides of the Atlantic, the US test is the one that will govern your image library in practice: The Model Wearing Your Frames Isn’t Real. In New York, You Have to Say So.

The two duties that are not yours — and what to do about them anyway

The chatbot label and the machine-readable marking belong to your vendors. That is not a reason to ignore them; it is a reason to handle them differently. You do not need a compliance programme. You need an answer in writing.

There is one date attached to this, and it is worth knowing precisely because it is the only AI Act deadline in the next twelve months that touches an ordinary store. It is Article 111(4), a transitional provision, and it reads:

“Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.”

Read the subject of that sentence: providers. If you generate product imagery with a tool that was already on the market in July, the catch-up obligation is the tool vendor’s, and 2 December 2026 is their deadline. It belongs on your calendar as a question to ask, not as a task to complete. Ask it in October, not in late November.

And label the chatbot regardless. It is one sentence in an opening message, it costs nothing, and the visible failure — a customer who thought they were talking to a dispensing optician — happens on your page and damages your brand, whoever the regulator would eventually pursue. “Hi, I’m Iris” does not clear the bar. “Hi, I’m Iris, an AI assistant” does.

The €15 million number is the wrong number for you

Nearly every article about Article 50 quotes the same penalty: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. That figure is accurate. It is Article 99(4), and Article 99(4)(g) does list the transparency obligations under Article 50.

Two paragraphs further down, Article 99(6) says this:

“In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.”

Lower, not higher. For a store with €2 million of turnover, 3% is €60,000, and €60,000 is the ceiling — not €15 million. The headline figure was never about you. It exists to reach a company for which 3% is the bigger number.

One more layer, and it cuts the same way: Article 99 sets the European ceiling, but Member States lay down the actual penalty rules and notify them to the Commission. The number that would ever reach you is national, and it is not the number in the headline.

None of which is an argument for ignoring Article 50. It is an argument for spending an afternoon on it rather than a budget.

Does device status change the answer? It does — and it is the same line as always

Every European regime we have looked at for eyewear has turned on the same question: what, in regulatory terms, is the object you are selling? It decided who carries the duties under product law, under accessibility law, and under the cyber resilience regime for smart glasses. It decides this one too, and the mechanism is unusually clean.

Article 6(1) makes an AI system high-risk only where both of two conditions are met: the system is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I; and that product is required to undergo a third-party conformity assessment before it goes on the market.

Annex I lists the Medical Devices Regulation (EU) 2017/745 at point 11 and the Personal Protective Equipment Regulation (EU) 2016/425 at point 9. Both of those govern eyewear. So the first limb is met easily. The second limb is where eyewear separates:

  • Corrective frames and lenses are Class I medical devices, and Class I self-certifies. No notified body, so the second limb fails — not high-risk under Article 6(1).
  • Non-prescription sunglasses are category I PPE, which also self-certifies. Same result.
  • Contact lenses are Class IIa, and Class IIa requires a notified body. The second limb is met — and an AI system that is a safety component of that device, or is that device, is high-risk.

Keep the scope of that straight, because it is easy to over-read. This is about AI inside the regulated product, not AI on your website. A lens configurator is not a safety component of a contact lens, and a recommendation engine is not a medical device because it recommends one. But if you are building or white-labelling software that ships as part of a Class IIa product, the classification you already established for compliance purposes has just told you your AI Act answer as well.

What about AI that reads prescriptions?

A tool that extracts written values from an uploaded prescription for a human to confirm is a document-processing tool. It is not diagnosing anything, and diagnosis is where device classification and high-risk treatment begin. Two design principles keep that comfortably true: the AI transcribes and the human confirms, and the system never issues, alters or interprets a prescription. The closer a tool moves to interpreting vision data rather than transcribing it, the more that question needs a real legal answer rather than a blog post’s.

And note separately that prescription data is health data under GDPR Article 9 whether or not any AI touches it. That obligation predates the AI Act and outweighs it for most merchants.

What actually changed this summer, and what did not

The deferral of the high-risk rules is settled and is no longer a proposal. The Digital Omnibus on AI is Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026. It moved these dates:

  • 2 December 2027 — Chapter III obligations for standalone high-risk systems under Annex III.
  • 2 August 2028 — the same obligations for high-risk AI embedded in the Annex I regulated products described above.
  • 2 December 2026 — new prohibitions inserted into Article 5 as points (ba) and (bb), covering AI systems that generate non-consensual intimate imagery and child sexual abuse material.
  • 2 December 2026 — the Article 111(4) catch-up for synthetic-content generators already on the market, described above.

It also quietly softened Article 4, the AI literacy duty. The original required providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff. As amended, they must take measures that support the development of AI literacy, and the provision now says explicitly that it does not require guaranteeing any particular level for any individual.

Softened is not removed, and this one is worth ten minutes because it is the AI Act obligation that has been binding on deployers — that is, on you — since 2 February 2025, and almost nobody has done anything about it. It does not require a course. A page of notes covering what each tool does, what it must not be used for, and who to ask, kept with a date on it, is a proportionate answer for a small store.

What did not change: Article 50 was not deferred. The transparency obligations applied from 2 August 2026 and still do. Prohibited practices and the AI literacy duty have applied since 2 February 2025, and general-purpose AI model obligations since 2 August 2025.

What to do this month

  1. List every AI system on the store, and write “provider” or “deployer” next to each. Chatbot, try-on, PD measurement, prescription reading, recommendations, generated imagery, generated copy. Most stores have more than they think, because several arrived inside apps. This one column decides everything else on this list.
  2. Ask the try-on vendor the recital 16 question. Can the feature run without displaying a product on the customer? Does anything downstream store the categorisation? If either answer is the wrong one, you have an Article 50(3) notice to write.
  3. Audit the image library for real people. Any picture that depicts an identifiable person doing something they did not do is the Article 50(4) case. If you sell into the US, apply the broader New York test instead and save yourself the analysis.
  4. Label the chatbot anyway. One sentence. Cheapest thing on this list.
  5. Get the Article 50(2) answer in writing, in October. Ask every generative tool vendor whether its output carries machine-readable marking, and if the tool predates 2 August 2026, whether it will meet the 2 December 2026 catch-up. Their answer is your evidence.
  6. Write half a page of AI literacy notes and date it. Article 4 has been live since February 2025.
  7. Check where face processing happens. On-device beats sending images to a server, both for the GDPR and for what you are able to promise a customer.
  8. Keep a human in the loop on prescriptions, and say so on the page. It is a compliance posture and a trust signal at the same time, for a customer handing over medical data.

The honest framing

None of this is a reason to take AI out of an eyewear store. The features under discussion — reading a prescription so nobody retypes it, measuring a pupillary distance so nobody is blocked on a number they do not have — are what make buying prescription eyewear online possible at all, and the Act was not written to stop them. The Commission wrote the try-on carve-out into its own recitals.

What the Act asks of a store at this level is honesty about what is automated, and it asks it in two specific places: when software is looking at a customer’s face, and when a picture shows something that did not happen. Those are the two duties that are yours. They are also the two questions a customer hesitating over a prescription upload is already asking.

Frequently asked questions

Does the EU AI Act apply to my store if I am not in the EU?

It can. The Act reaches providers and deployers established outside the Union where the output of the system is used in the Union. If you sell to EU customers and run AI features for them, assume you are in scope and work out which role you are in.

Do I have to label my chatbot as AI?

The duty in Article 50(1) is on the provider of the system, which for an off-the-shelf app is the vendor, not you. Label it anyway: it is one sentence, and the reputational failure happens on your page regardless of whose legal duty it was.

Is virtual try-on a biometric categorisation system under the AI Act?

Usually not. Article 3(40) excludes categorisation that is ancillary to another commercial service and strictly necessary for objective technical reasons, and recital 16 gives the example of marketplace filters that let a consumer preview a product on themselves. The exclusion falls away if the categorisation is stored, reused for marketing, shared with third parties, or offered as a standalone feature — and then the Article 50(3) notice duty is yours as deployer.

Do I have to disclose AI-generated product images in Europe?

Article 50(4) covers deep fakes, defined in Article 3(60) as content resembling existing persons, objects, places or events that would falsely appear authentic. A wholly synthetic model resembling no real person is a weaker case than most coverage implies. The machine-readable marking duty in Article 50(2) is a separate obligation and it sits on the provider of the generating tool. Note that New York’s disclosure law is broader and does not require a real person to be depicted.

What is the penalty for getting Article 50 wrong?

Article 99(4) sets a ceiling of €15 million or 3% of total worldwide annual turnover, whichever is higher — but Article 99(6) provides that for SMEs, including start-ups, the fine is capped at whichever of those is lower. For most stores that is the percentage, and it is a far smaller number. Member States set the actual penalty rules nationally.

Were the high-risk rules really delayed?

Yes, and it is settled. Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026. Annex III high-risk obligations now apply from 2 December 2027 and Annex I ones from 2 August 2028. The Article 50 transparency duties were not deferred.

Is there anything on the AI Act calendar before December 2027?

Yes — 2 December 2026. The new Article 5 prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material take effect, and under Article 111(4) providers of synthetic-content generators that were already on the market before 2 August 2026 must meet the Article 50(2) marking obligation by that date.

Is AI that reads prescriptions high-risk?

Not straightforwardly. Article 6(1) requires the system to be a safety component of, or itself be, an Annex I product and for that product to require third-party conformity assessment. Corrective frames and lenses are Class I medical devices and self-certify, so that second limb is not met. A transcription tool with a human confirming the values is a document-processing tool in any event. Take advice if your tool does anything beyond extraction.

Is this the same as the GDPR?

No, and the GDPR is the one more likely to bite an eyewear store first. Prescription data is health data under Article 9 and face mapping is biometric-adjacent, both carrying obligations that exist independently of the AI Act and predate it.


This article is general information about regulatory developments, not legal advice. Rules of this kind apply differently depending on your catalogue, your suppliers, your vendors and where you sell; take advice on your own position before acting.


VisioncarePro reads uploaded prescriptions into structured values that the customer confirms before the order proceeds — the AI transcribes, the human decides. Prescription data is encrypted in transit and at rest and handled under documented controls. Free to install.

Install VisioncarePro free on the Shopify App Store →


Sources: Regulation (EU) 2024/1689 (AI Act), Articles 3(3), 3(4), 3(40), 3(60), 4, 5, 6(1), 25, 50, 99, 111(4) and 113, recital 16 and Annex I · Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), in force 27 July 2026 · Regulation (EU) 2017/745 (Medical Devices) · Regulation (EU) 2016/425 (Personal Protective Equipment) · GDPR Article 9.

RuffRuff Apps RuffRuff Apps by Tsun