AI-driven product recommendations and individualised pricing are now standard infrastructure in fashion e-commerce. What is less settled is the legal framework that governs them. Three overlapping EU instruments — the Modernisation Directive (commonly called the Omnibus Directive), the Unfair Commercial Practices Directive (UCPD), and the EU AI Act — each impose distinct obligations on operators who deploy these systems. Understanding where those obligations intersect is not optional: enforcement is active, and the consequences of non-compliance range from injunctions to significant administrative fines.
Key takeaways
- The Omnibus Directive requires explicit disclosure whenever a price shown to a consumer has been personalised using automated profiling.
- The UCPD prohibits AI recommendation systems from exploiting consumer vulnerabilities in ways that distort economic behaviour.
- The EU AI Act classifies certain emotion-recognition and behavioural-manipulation systems as prohibited or high-risk, with direct implications for fashion recommendation engines.
- Transparency obligations under GDPR and the AI Act overlap but are not identical: satisfying one does not automatically satisfy the other.
- Legal and product teams need a shared compliance checklist that covers all three instruments simultaneously, not sequentially.
What does the Omnibus Directive actually require from fashion retailers?
The Omnibus Directive (Directive 2019/2161, transposed by Member States from May 2022) amended four existing consumer-protection directives to address digital market realities. For fashion e-commerce, the most operationally significant change is the mandatory disclosure of personalised pricing.
Where a trader uses automated decision-making — including machine-learning recommendation engines — to present a price that has been adapted to a specific individual based on profiling, the consumer must be informed that the price is personalised. This obligation applies before the consumer commits to a purchase. A small-print reference buried in a privacy policy does not satisfy it.
The directive also tightened rules on consumer reviews. If a fashion platform aggregates or displays product ratings, it must disclose whether and how it verifies that reviews come from genuine purchasers. AI-curated review summaries that suppress negative signals without disclosure are directly in scope.
Practically, this means your checkout and product-detail-page templates need a visible, plain-language notice whenever a personalised price is rendered. The notice cannot be conditional on the consumer navigating to a settings page.
How does the UCPD apply to AI recommendation engines?
The Unfair Commercial Practices Directive (2005/29/EC), as updated by the Omnibus Directive, prohibits commercial practices that are misleading or aggressive. AI recommendation systems can fall foul of both categories.
Misleading practices
A recommendation engine that presents algorithmically ranked results as if they were editorially curated, or that promotes products on the basis of commercial arrangements without disclosing this, engages in a misleading practice. In fashion e-commerce, this is common: sponsored placements inside a 'recommended for you' carousel, or search results ranked partly by margin rather than relevance, are UCPD-sensitive if the ranking logic is not disclosed.
The UCPD's Annex I contains a blacklist of practices that are always unfair, regardless of context. Disguising commercial communications as organic recommendations is on that list.
Aggressive practices and vulnerability exploitation
The UCPD prohibits practices that use harassment, coercion, or undue influence to impair a consumer's freedom of choice. Research into AI-driven personalisation and impulsive buying in e-commerce — published in Frontiers in Research Metrics and Analytics — identifies the mechanism by which personalised nudges can exploit cognitive biases to drive impulsive purchases. Regulators in several Member States have begun treating this class of design pattern as a candidate for UCPD enforcement.
For fashion specifically, the concern is acute: recommendation engines trained on purchase history can identify consumers who exhibit impulsive buying tendencies and serve them urgency signals ('only 2 left') or time-limited discounts at moments of peak susceptibility. Whether this constitutes 'undue influence' under Article 9 UCPD is a live question in several national courts.
Where does the EU AI Act intersect with personalisation systems?
The EU AI Act, which entered into force in August 2024 and is being phased in through 2026 and beyond, introduces a risk-tiered framework for AI systems. Fashion recommendation and pricing engines are not automatically high-risk, but several configurations can push them into regulated territory.
Prohibited systems
Article 5 of the Act prohibits AI systems that deploy subliminal techniques or exploit vulnerabilities of specific groups to distort behaviour in ways that cause harm. A recommendation engine that has been trained to identify and target consumers with compulsive spending patterns, and that uses that signal to intensify promotional pressure, is a credible candidate for this prohibition. The boundary between permitted personalisation and prohibited manipulation is not yet fully defined by guidance, but Taylor Wessing's sector analysis notes that fashion AI systems are generally treated as low-risk under the Act — with the important caveat that the specific use case, not the industry, determines the classification.
Transparency obligations for AI-generated outputs
Where an AI system interacts directly with consumers — a chatbot that recommends outfits, a virtual stylist that curates a basket — the Act requires that consumers be informed they are interacting with an AI. This obligation applies regardless of risk tier. It is separate from, and additional to, the UCPD disclosure requirements described above.
General-purpose AI and recommender systems
Large fashion platforms that deploy general-purpose AI models (foundation models fine-tuned for recommendation) will also need to account for the Act's provisions on model transparency and systemic risk. This is an emerging area; the European AI Office is expected to issue further guidance through the course of the implementation period.
How do GDPR obligations layer on top?
GDPR is the foundational layer. Personalised pricing and recommendation both rely on profiling, which under Article 22 GDPR gives consumers the right not to be subject to solely automated decisions that produce legal or similarly significant effects. Whether a personalised price constitutes a 'significant effect' is contested, but the safer interpretation — adopted by several data protection authorities — is that it does.
This means fashion retailers should be able to offer a human-review pathway for consumers who object to automated pricing, and should document the logic of their profiling systems in a way that supports meaningful explanation to both consumers and regulators.
A thesis examining AI-driven personalisation and consumer trust in the EU context, available via the DiVA research portal, notes that GDPR compliance and consumer trust are correlated but not equivalent: consumers who understand how their data is used are more likely to accept personalisation, which has commercial as well as compliance implications.
What does this mean in practice for fashion e-commerce teams?
Zalando, operating across 29 European markets and connecting tens of millions of active customers with thousands of brands, is an example of the operational scale at which these obligations become structurally complex. At that scale, a single recommendation engine may interact with consumers across multiple Member State jurisdictions, each with its own transposition of the Omnibus Directive and its own enforcement posture.
For product and legal teams, the practical implication is that compliance cannot be treated as a one-time legal review. It requires ongoing collaboration between engineering (who control the model logic), product (who design the user-facing disclosure), and legal (who track regulatory developments). Platforms such as Vue.ai, which offer modular AI orchestration for retail personalisation journeys, increasingly document their compliance posture as part of enterprise procurement conversations — a signal that the market is beginning to treat regulatory alignment as a product feature rather than an afterthought.
A working compliance checklist
The following items represent the minimum a fashion e-commerce operator should be able to demonstrate:
- Personalised pricing disclosure: a visible, pre-purchase notice on every product or checkout page where a personalised price is rendered.
- Recommendation ranking disclosure: a clear statement of the primary factors that determine recommendation order, including any commercial weighting.
- AI interaction disclosure: a consumer-facing notice wherever an AI system (chatbot, virtual stylist, automated customer service) is the primary interface.
- Profiling legal basis: documented lawful basis under GDPR Article 6 for each profiling activity that feeds the recommendation or pricing engine.
- Automated decision-making pathway: a human-review option for consumers who object to automated pricing decisions.
- Vulnerability audit: a documented assessment of whether the recommendation engine's training data or optimisation objective creates a risk of targeting vulnerable consumers.
- Model documentation: internal records sufficient to explain the recommendation or pricing logic to a regulator on request.
What remains unsettled?
Several questions are genuinely open and will be resolved through enforcement decisions and court judgments over the coming years.
First, the threshold at which personalised pricing becomes a 'significant effect' under GDPR Article 22 has not been authoritatively determined across all Member States. Until it is, operators face legal uncertainty that no compliance programme can fully eliminate.
Second, the boundary between permitted personalisation and prohibited manipulation under the EU AI Act's Article 5 prohibition will depend heavily on guidance from the European AI Office, which is still being developed.
Third, the interaction between the AI Act's transparency obligations and the UCPD's disclosure requirements has not been tested in enforcement. It is possible that satisfying one creates a presumption of compliance with the other; it is equally possible that regulators will treat them as entirely independent.
Fourth, the question of how recommendation engines should handle consumers who have exercised GDPR opt-outs from profiling — while still receiving some form of product discovery assistance — is operationally complex and legally underspecified.
For legal and product teams, the prudent approach is to design for the stricter interpretation of each obligation, document the reasoning, and build review cycles into the product roadmap rather than treating compliance as a project with an end date.
FAQ
Does every AI recommendation engine in fashion e-commerce need a disclosure notice? Not every engine triggers the same disclosure. Personalised pricing always requires an explicit notice. Recommendation ranking requires disclosure of the primary factors, including commercial weighting. AI-to-consumer interaction (chatbots, virtual stylists) requires a notice that an AI is involved. Systems that use only aggregate, non-individualised logic may fall outside the personalised-pricing rule.
What is the difference between the Omnibus Directive and the UCPD for fashion retailers? The Omnibus Directive amended existing directives — including the UCPD — to address digital practices. The UCPD is the substantive instrument that defines unfair practices. Think of the Omnibus Directive as the update package and the UCPD as the operating system. Both apply simultaneously; satisfying the Omnibus Directive amendments does not exhaust UCPD obligations.
Is personalised pricing illegal under EU law? No. Personalised pricing is permitted, but it must be disclosed before purchase. The obligation is transparency, not prohibition. A consumer who is informed that a price has been personalised can still choose to proceed or to seek an alternative.
How does the EU AI Act affect fashion recommendation systems specifically? Most recommendation systems will be classified as low-risk under the Act. The exceptions are systems that use subliminal techniques, exploit consumer vulnerabilities, or deploy emotion recognition in ways that affect purchasing decisions. The transparency obligation — disclosing AI involvement in consumer-facing interactions — applies across all risk tiers.
What should a fashion retailer do if it cannot determine whether its pricing engine meets the personalised-pricing disclosure threshold? Apply the disclosure anyway. The cost of an unnecessary notice is negligible. The cost of an enforcement action for failing to disclose is not. Where the legal position is uncertain, the conservative approach is also the commercially rational one.
Further reading
- AI-driven personalization and impulsive buying in e-commerce — Frontiers in Research Metrics and Analytics
- AI-Driven Personalization and Consumer Trust — DiVA portal
- Fashion meets the AI Act — Taylor Wessing
- AI-driven personalization and impulsive buying in e-commerce — PMC
