Almost everything written about the rules of agentic commerce is written from the United States. It reasons about Regulation E, about chargeback rights under the Electronic Fund Transfer Act, about who eats the loss when an agent buys the wrong thing. Those are real questions and they have American answers.
If you run a WooCommerce store in the European Union, that literature tells you very little, and it misses the two things that actually affect you: a deadline that passed on 2 August 2026, and a structural gap in consent that no regulator has closed.
This is a merchant’s map of the European position as of late August 2026.
First, the deadline — and why it is smaller than it sounds
Article 50 of the EU AI Act became practically relevant for online retailers on 2 August 2026, and systems placed on the market from that date get no grace period.
Article 50 is the transparency chapter. The paragraph most often quoted at merchants requires that AI systems intended to interact directly with natural persons be designed so those persons are informed they are dealing with an AI, unless it is obvious from the circumstances. A second obligation covers synthetic audio, image, video and text, which must be marked as artificially generated.
Here is the part most of the alarmed commentary leaves out: that obligation falls on the provider of the AI system, not on the shop that uses it. If you have a chatbot on your storefront, the disclosure duty attaches to whoever built and placed that system on the market. If you use an AI writing tool to draft product descriptions, the marking obligation attaches to the tool.
That is not a reason to ignore it. It is a reason to ask your vendors one specific question — “how do you satisfy Article 50, and what does that leave to me?” — instead of buying compliance theatre for a duty that is not yours.
What already applied to you, and still does, is more mundane and more enforceable: misleading product copy has been prohibited for years under unfair commercial practices law. The AI Act did not change that. It sharpened the focus on factual accuracy.
Second: consumer law follows the decision, not the decider
On 9 March 2026 the UK Competition and Markets Authority published its work on agentic AI and consumers alongside guidance for businesses. The framing is pro-innovation, but the core holding is blunt: existing consumer protection rules apply when companies use agentic AI in consumer-facing contexts. Consumer law does not care whether a person or a model made the decision.
On 31 March, four UK regulators — the CMA, the Financial Conduct Authority, the ICO and Ofcom — published the Digital Regulation Cooperation Forum’s foresight paper on agentic AI together. On 8 June, the European Data Protection Supervisor and the German federal and Bavarian data protection authorities held a high-level debate on the proposed Digital Omnibus and its implications for this area.
The pattern across all of it is worth naming: regulators are publishing foresight papers and guidance rather than rules, because the technology is outrunning the legislative cycle. The Digital Fairness Act, announced in the Commission’s 2026 work programme and expected to address dark patterns and digital product design, is not expected in first draft until the end of this year.
So the practical answer to “what are the rules for agentic commerce in Europe” is: the old rules, applied to a new fact pattern, by regulators still working out what the fact pattern is. Anyone selling you certainty about this right now is selling you something.
The CMA’s own expectations read like a description of ordinary competence — be transparent about agentic AI use with accurate claims about capability, respect consumers’ statutory and contractual rights, monitor real-world performance for errors and complaints with human oversight, remediate promptly. The enforcement backstop is not ordinary: failure to comply with consumer protection law can reach fines of up to 10% of worldwide turnover.
Third, and largest: the consent architecture has lost its subject
Here is the gap, and it is the reason this article exists.
The entire consent apparatus the European web built over the last decade — the banner, the granular toggles, the legitimate-interest arguments, the records of who agreed to what and when — rests on an assumption so basic it was never written down: there is a human being looking at a screen at the moment consent is given.
Agentic commerce quietly removed that human. When an agent visits your store, reads your catalog and completes a purchase on someone’s behalf, who was shown the banner? Who accepted? An agent can be made to click “accept all” trivially, and that click means nothing, because the entity that clicked is not the data subject and cannot exercise the rights the click is supposed to waive.
Nobody has a settled answer. What has been published so far is early, and the honest practitioners in this space say openly that this one is genuinely hard.
A few positions look defensible under every reading published so far, and are worth adopting now precisely because they cost little:
- Treat agent-driven visits as unconsented for anything beyond what the transaction itself requires. No analytics profiling, no marketing cookies, no personalisation on the basis of an agent session — not because a rule says so, but because there is no coherent account of who consented.
- Do not treat an agent’s acceptance as the user’s acceptance. If your flow requires consent to something material, that consent needs a human somewhere in the chain, and your records should be able to show where.
- Keep the data you collect from agent traffic to what the order needs. This is data minimisation, which is not new, and which happens to be the only position that survives regardless of how the question is eventually resolved.
What this means in practice
The three defensible positions above already answer most of the actionable question, and none of them requires special infrastructure. They are decisions about consent posture and about data collection, and they can be adopted today.
There is one further decision worth making early, and it is independent of how the consent question is eventually settled: keep the checkout and the customer relationship on a surface where a human is reachable and where there is a record.
Whatever the regulator eventually concludes about agent sessions, the consent and liability questions are going to be answered against whoever was standing in the transaction. If the purchase flows through a surface you control — your checkout, your order record, your customer relationship — you can produce evidence about what a human agreed to, and you can show the record when it matters. If the transaction ran on someone else’s surface, you will be relying on someone else’s records, and on someone else’s ability and willingness to recover the paper trail on your behalf.
This is not a technological position. It is a books-and-records position. It says: make sure the part of the sale that produces legal obligations lives somewhere you can account for. Whether that means keeping checkout on your own domain, or negotiating a clear record-sharing commitment with the platform you already use, is a commercial decision only you can make — the principle is the same either way.
What a plugin cannot do for you
A catalog layer solves the machine-readability problem. It does not solve your legal obligations, and the boundary is worth stating explicitly.
- Your imprint, legal notice and trader identification obligations remain yours.
- Your right-of-withdrawal handling remains yours.
- Whether your particular use of an AI tool triggers a duty under the AI Act depends on what the tool is and who placed it on the market. Ask the vendor, in writing.
- Nothing here substitutes for advice from a lawyer who practises e-commerce law in your jurisdiction.
The short version
The Article 50 deadline has passed, and for most merchants it points at your vendors rather than at you. Consumer law already applies to agent-mediated sales exactly as it applies to human ones, with enforcement powers that make that worth taking seriously. And the real open question — who consented, when there was no human in the session — has no answer yet, which makes minimising what you collect from agent traffic the only position that is safe under every outcome.
Europe is behind the United States on agentic commerce infrastructure and ahead of it on the rules. For a European merchant that is not a disadvantage. It means the constraints you will operate under are already visible, and you can build for them now instead of retrofitting later.
Sources
- EU AI Act for Online Retailers: What Shop Operators Need to Know in 2026
- EU AI Act 2026: AI Agents Must Now Say They’re AI
- European Digital Compliance: Key Digital Regulation Developments (May 2026) — Morrison Foerster, on the CMA agentic AI publications
- AI agents are shopping on your behalf. No one knows the rules yet — iubenda, on the consent gap
- 2026 update: EU regulations for tech and online businesses — Reed Smith
- Related: The EU withdrawal button in WooCommerce · Agentic commerce after checkout