The EU AI Act establishes a tiered risk framework that applies to any AI system placed on the European market or used within the EU—regardless of where its developer is headquartered. For fashion companies, that means the demand-forecasting models, personalisation engines, recruitment screening tools, and biometric processing pipelines already running in production must be assessed against the Act's classification criteria. The classification determines your obligations: from near-zero requirements at the minimal-risk end to mandatory conformity assessments, technical documentation, and human-oversight mechanisms at the high-risk end.
Key takeaways
- Most fashion AI systems—product recommendations, trend forecasting, chatbots—fall into the minimal or limited risk tiers and face primarily transparency obligations.
- AI systems used in recruitment, workforce management, or access control in employment contexts are classified as high-risk under Annex III and carry the Act's heaviest compliance burden.
- Biometric categorisation systems that infer sensitive attributes from images are prohibited or high-risk depending on their purpose and the data they process.
- Demand-forecasting tools sit in a grey zone: their classification depends on how consequential their outputs are and whether a human decision-maker remains in the loop.
- The Act's obligations are not static—providers and deployers share responsibility, and the split matters for product teams procuring third-party AI.
What does the EU AI Act's risk framework actually look like?
The Act organises AI systems into four broad categories.
Unacceptable risk (prohibited): Systems that the Act bans outright. These include social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), and AI that exploits psychological vulnerabilities to manipulate behaviour. Fashion brands are unlikely to deploy systems that fall squarely here, but certain loyalty or behavioural-profiling architectures warrant scrutiny.
High risk: Systems listed in Annex III or embedded in safety-critical products covered by existing EU harmonisation legislation. Annex III is the list that matters most for fashion companies. It covers, among other categories: AI used in employment, worker management, and access to self-employment—including systems that screen CVs, rank candidates, monitor performance, or allocate tasks.
Limited risk: Systems that interact with humans (chatbots, virtual assistants) or generate synthetic content. The main obligation is transparency: users must know they are interacting with an AI, and AI-generated content must be labelled.
Minimal risk: Everything else. Product recommendation engines, visual search, most trend-analytics tools, and inventory optimisation models that feed into human decisions without directly determining them typically land here. No mandatory obligations apply, though the Act encourages voluntary codes of conduct.
How does demand forecasting map to the risk tiers?
Demand forecasting is the use case most fashion AI teams encounter first, and its classification is genuinely contested.
The Act does not list demand forecasting in Annex III. A system that analyses historical sales, social-image signals, and macroeconomic indicators to produce a probabilistic range of future demand—where a human merchandiser then makes the final buy decision—is almost certainly minimal risk. The system informs; it does not determine.
The picture shifts when the model's output directly triggers automated purchasing commitments, supplier contracts, or workforce scheduling without meaningful human review. At that point, the system begins to resemble an autonomous decision-making tool whose errors carry material economic consequences for workers and suppliers. Whether that tips it into high risk depends on the specific deployment architecture and who is affected. Your legal team should assess whether affected workers fall under the employment-management provisions of Annex III.
Platforms such as Heuritech—now part of Luxurynsight's luxury data-intelligence platform following its acquisition—provide social-image trend and demand signals that feed into human-led planning processes. That architecture, where outputs are advisory and a human makes the consequential call, is the design pattern that keeps a forecasting tool in the minimal-risk tier.
What about personalisation and recommendation engines?
Personalisation covers a wide range of systems: product recommendations, dynamic pricing, size suggestions, and targeted marketing. Most of these are limited or minimal risk under the Act.
The transparency obligation for limited-risk systems is the key practical requirement. If your personalisation layer involves a conversational interface—a styling chatbot, a virtual assistant—users must be informed they are interacting with an AI. That disclosure must be clear, not buried in terms of service.
Dynamic pricing deserves separate attention. A system that adjusts prices in real time based on inferred user characteristics—particularly if those characteristics include protected attributes—could attract scrutiny under both the AI Act and the General Data Protection Regulation. The Act does not prohibit dynamic pricing, but deployers should document the logic, test for discriminatory outcomes, and ensure the system does not exploit psychological vulnerabilities in a way that crosses into prohibited manipulation.
Vue.ai offers an enterprise AI orchestration platform covering product tagging, personalised eCommerce journeys, and inventory demand forecasting. Systems of this type, used to surface relevant products to shoppers, sit comfortably in the minimal-risk tier—provided the personalisation logic does not make decisions about access to services in a way that disadvantages protected groups.
Which fashion AI use cases are classified as high risk?
This is where product and governance teams need to focus the most attention. Annex III of the Act lists high-risk categories that are directly relevant to fashion operations.
Recruitment and workforce management
Any AI system used to filter CVs, score candidates, rank applicants, or make or substantially influence hiring decisions is high risk. The same applies to systems that monitor worker performance, allocate tasks, or determine access to employment opportunities—including gig-economy platforms that assign work to freelance pattern cutters or warehouse staff.
If your organisation uses an AI-assisted applicant tracking system, or if a third-party HR platform you have procured uses AI to rank candidates, you are a deployer of a high-risk system. That carries concrete obligations:
- Technical documentation: The provider must supply documentation covering the system's design, training data, performance metrics, and known limitations before deployment.
- Conformity assessment: High-risk systems must undergo a conformity assessment—either self-assessment against harmonised standards or, for certain categories, third-party assessment.
- Human oversight: You must designate a natural person responsible for overseeing the system's outputs and capable of overriding or halting it.
- Logging and audit trails: The system must generate logs sufficient to allow post-hoc review of its decisions.
- Registration: High-risk AI systems must be registered in the EU database before being placed on the market or put into service.
As Taylor Wessing's sector analysis notes, fashion companies are currently working through the implications of these requirements, particularly for tools procured from third-party vendors where the provider-deployer responsibility split is not always obvious.
Access control and worker monitoring
AI systems used to control physical access to workplaces—factory floors, distribution centres—or to monitor workers' behaviour, productivity, or emotional state in the workplace are also high risk under Annex III. Fashion supply chains that use computer-vision systems to monitor sewing-line throughput or detect worker fatigue should assess whether those systems meet the Act's definition of an AI system and, if so, what tier they occupy.
What does biometric processing mean for fashion AI?
Biometric processing is the area where the Act's most serious prohibitions apply, and it is more relevant to fashion than it might initially appear.
Virtual try-on and body measurement: Systems that capture body dimensions to recommend sizing are processing biometric data in the broad sense. Whether they constitute a biometric identification system under the Act depends on whether they are used to identify individuals—most sizing tools are not, because they process measurements without linking them to a persistent identity. These systems are generally minimal or limited risk, though GDPR obligations around biometric data remain in force independently of the AI Act.
Biometric categorisation: A system that infers attributes such as age, gender, ethnicity, or emotional state from images is a biometric categorisation system. The Act prohibits using such systems to infer sensitive attributes (race, political opinion, religious belief, sexual orientation) in most contexts. Fashion brands that use computer-vision tools to segment shoppers by inferred demographic attributes should audit those tools carefully. If the model is inferring protected characteristics from visual data, the system may be prohibited outright.
Emotion recognition in retail: AI systems that claim to infer emotional states from facial expressions are explicitly addressed in the Act. Their use in the workplace and in educational settings is prohibited; their use in other contexts—such as retail environments—is not categorically banned but is high risk and subject to transparency obligations.
How does the provider-deployer split affect fashion companies?
The Act distinguishes between providers (those who develop and place an AI system on the market) and deployers (those who use it in a professional context). Most fashion brands are deployers, not providers. That distinction matters because the heaviest obligations—conformity assessments, technical documentation, registration—fall primarily on providers.
But deployers are not obligation-free. You must:
- Use the system only for its intended purpose as described by the provider.
- Implement human oversight measures.
- Monitor the system for risks that emerge in your specific deployment context.
- Inform the provider of serious incidents.
- Ensure affected workers and users receive the disclosures the Act requires.
When you procure a third-party AI tool, the contract should specify which party is the provider for Act purposes, what technical documentation the provider will supply, and how incident reporting will work. Procurement teams that treat AI tools like any other SaaS purchase—without reviewing these obligations—are creating compliance exposure.
What is still unresolved?
The Act is in force, but several implementation details remain unsettled.
Harmonised standards: The European standardisation bodies are still developing the technical standards that providers can use to demonstrate conformity. Until those standards are finalised, providers must interpret the Act's requirements directly—a more demanding exercise.
General-purpose AI models: The Act introduces obligations for providers of general-purpose AI models (GPAIs) with systemic risk. Fashion companies that fine-tune foundation models on proprietary data should assess whether that activity makes them a provider of a GPAI.
Global reach: Research published in Policy & Society examines whether the Act will produce a Brussels effect—raising standards globally—or whether its influence will be more limited. The answer matters for fashion brands with supply chains and customer bases outside the EU, who may face divergent regulatory requirements in different markets.
SME provisions: The Act includes reduced obligations for small and medium-sized enterprises, but the thresholds and practical scope of those reductions are still being clarified through guidance from the AI Office.
A practical classification checklist for fashion AI teams
Before deploying or procuring an AI system, work through these questions:
- Does the system fall within a category listed in Annex III? If yes, treat it as high risk until you have legal advice confirming otherwise.
- Does the system interact with users through a conversational interface or generate synthetic content? If yes, transparency obligations apply.
- Does the system process biometric data? If yes, identify whether it is being used for identification, categorisation, or neither—and check whether the inferred attributes are protected.
- Is the system's output directly determining a consequential decision, or is a human making the final call? The answer affects both the risk tier and the design requirements.
- Are you the provider or the deployer? Identify which party bears which obligations before signing the contract.
FAQ
Is demand forecasting AI classified as high risk under the EU AI Act? Generally no—demand forecasting tools that produce advisory outputs reviewed by human decision-makers are minimal risk. The classification can shift if the system autonomously triggers employment or procurement decisions without meaningful human oversight.
Do fashion chatbots and styling assistants have compliance obligations? Yes. Conversational AI systems are limited-risk under the Act and must disclose to users that they are interacting with an AI. The disclosure must be clear and timely, not buried in terms and conditions.
What makes a recruitment AI system high risk in fashion? Any system that filters CVs, ranks candidates, or substantially influences hiring or task-allocation decisions is listed in Annex III as high risk. This applies whether the system is built in-house or procured from a third-party HR platform.
Can fashion brands use AI to analyse shoppers' facial expressions in stores? Emotion recognition in retail is not categorically prohibited, but it is high risk and subject to strict transparency and oversight requirements. Systems that infer protected attributes from facial data may be prohibited outright.
Who is responsible for compliance when a fashion brand uses a third-party AI tool? Both the provider and the deployer carry obligations. Providers bear the heaviest technical and documentation requirements; deployers must use the system as intended, implement oversight, and monitor for risks in their specific context. Contracts should allocate these responsibilities explicitly.
When do the EU AI Act's high-risk obligations take effect? The Act entered into force in stages. Governance leads should verify current applicability dates with legal counsel, as transitional periods vary by system category and provider type.
Further reading
- Fashion meets the AI Act — Taylor Wessing sector analysis
- Brussels effect or experimentalism? The EU AI Act and global AI governance — Policy & Society
