🛒 AI rules: Retail, e-commerce, customer service
Chatbots, recommendations and dynamic pricing are everyday AI in retail — mostly minimal risk, but consumer law makes you responsible for what your AI says and does.
Typical AI uses and their risk level
Say it is AI; answers bind you; accessibility for e-shops.
Minimal — but descriptions must be accurate (misleading practices).
Disclose that the price is personalised by automated decision-making.
Credit scoring = high risk.
Prohibited biometric categorisation.
What to do
- Add an AI notice to the chatbot and a clear path to a person.
- Test the chatbot against your terms: prices, returns, warranties.
- Check accessibility of AI interfaces.
- Disclose personalised pricing.
Common pitfalls
- A bot that makes cancellation or complaints hard may be an aggressive practice.
- Free chatbot plugins often send customer data to third countries — check the DPA.
Examples
The customer may claim it. Limit the bot to verified knowledge and test regularly.
Rules that apply
Applies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.
In forceConsumer Protection Act (ZVPot-1)What your chatbot promises binds you. AI-personalised prices must be disclosed in online sales, and AI-generated fake reviews are a banned practice.
In forceEuropean Accessibility ActIf a chatbot or voice assistant is the way customers reach your service, it must also be accessible (e.g. usable with a screen reader, with a text alternative to voice). AI can help — automatic image descriptions, captions — but results must be checked.
In forceGDPRFor most companies GDPR matters more than the AI Act: it decides whether you may put customer or employee data into an AI tool at all. In Slovenia it is supplemented by ZVOP-2 and supervised by the Information Commissioner.
In forceDigital Services ActRecommender systems and content moderation are often AI: platforms must explain the main parameters and, for very large platforms, offer a feed not based on profiling. Very large platforms must assess risks from generative AI (e.g. deepfakes in elections).
PlannedDigital Fairness ActAI chatbots and AI-driven personalisation are among the topics — e.g. a possible right to reach a human instead of a chatbot.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.