EU Compliance in 2026: EU AI Act, Withdrawal Button & Shopify Stack
Damian Klimarczyk
English | EU AI Act (Article 50) | EU AI Label App vs Compliance Apps
9 minute read
Selling to EU consumers from Shopify in 2026 means watching two different clocks. The electronic withdrawal button function under Directive (EU) 2023/2673 has been mandatory since 19 June 2026. Deployer transparency under the EU AI Act (Regulation (EU) 2024/1689, Article 50) starts 2 August 2026 for AI-generated or materially AI-altered visuals that shoppers could mistake for real.
Those are separate laws. You need a working online withdrawal path for buyers, and you need visible disclosure on AI product photos at first exposure. We use Consentmo for withdrawal, cookies, and the wider privacy stack. We built EU AI Label for the Article 50 photo-labeling job.
Not legal advice. Confirm obligations with counsel for your markets, products, and customer base.
What landed in 2026, and what is next
EU ecommerce rules stack. They did not line up on one compliance day.
| Requirement | Legal basis | Status in 2026 | Who it affects |
|---|---|---|---|
| 14-day right of withdrawal | Consumer Rights Directive | Long-standing | B2C distance contracts for eligible goods/services |
| Electronic withdrawal function | Directive (EU) 2023/2673, Art. 11a CRD | Live since 19 June 2026 | Online stores selling to EU consumers |
| GDPR / ePrivacy | GDPR, ePrivacy framework | Ongoing | Stores processing EU personal data |
| Deployer AI transparency | EU AI Act, Article 50(4)/(5) | From 2 August 2026 | Anyone publishing AI-generated or AI-manipulated content that could pass as real |
| Provider machine-readable marking | EU AI Act, Article 50(2) | Grace period to 2 December 2026 for some systems | AI tool vendors, not your main deployer task |
June 2026 was about returns and contract withdrawal. August 2026 is about what shoppers see on product pages under the EU AI Act. Fixing one does not cover the other.
Shopify’s own guidance points merchants toward self-serve returns plus a dedicated electronic withdrawal function. See Shopify’s EU right of withdrawal help page.
The EU withdrawal button

What the law requires
Directive (EU) 2023/2673 added Article 11a to the EU Consumer Rights Directive. For in-scope online B2C contracts, you must give consumers an electronic withdrawal function: a clearly labeled button or link that lets them withdraw online without printing PDFs or hunting for a support email.
If you sell goods, services, or digital content to EU consumers through an online interface, you are usually in scope no matter where your company is registered.
A setup that survives scrutiny typically has four pieces:
-
A visible function with statutory wording (“Withdraw contract”, “Confirm withdrawal”).
-
Guest access. Buyers who did not create an account still need a path as easy as logged-in customers get.
-
Two steps: start withdrawal, then confirm identity and order details so accidental clicks do not count.
-
Automatic confirmation by durable medium (email works) with a timestamp when the request is submitted.
What happens when stores skip it
Enforcement varies by member state, but the downside is concrete. Some countries discuss fines up to 4% of annual turnover. If the required function is missing or broken, the standard 14-day cooling-off period can stretch to 12 months and 14 days in some cases. Ad-hoc “email us to cancel” workflows also leave you with messy records when a buyer or regulator pushes back.
DIY vs buying an app
You can build a custom withdrawal page, wire Shopify Flow emails, and add footer links yourself. The hard part is wording, guest access, confirmation emails, evidence trails, and product exemptions all holding up when tested.
Most Shopify merchants we talk to buy a compliance app that runs the full flow, not a contact form with compliance branding.
Why we recommend Consentmo
We partner with Consentmo because EU storefront compliance is rarely one checkbox. Cookie consent, privacy policy tooling, and withdrawal usually live in the same operational bucket. Consentmo put EU Withdrawal inside the Privacy Center merchants already use for GDPR.
We label AI product photos with EU AI Label. Consentmo handles consumer rights and privacy, the problems stores were already working on before Article 50 showed up.
What Consentmo’s withdrawal product does
Consentmo’s Withdraw Contract flow is customer-facing, not a footer link generator.
Buyers get a “Withdraw contract” page without logging in, plus an auto-added footer link for the cooling-off period. Enterprise plans can add an Order Status block so withdrawal starts from the order, not a generic form.
The flow uses statutory labels (“Withdraw contract”, “Confirm withdrawal”), order number + email verification, item selection, and final confirmation. Customers and merchants both get confirmation emails. The in-app log stores timestamps, order numbers, selected items, customer email, and reference IDs. You can export CSV for audits.
Consentmo does not auto-cancel every order or auto-refund every request. Your team still reviews eligibility: custom goods, perishables, opened hygiene seals, digital content with accepted immediate delivery, and other exemptions need a human decision. Blind automation is how stores refund orders that were never legally eligible.
Setup: Consentmo dashboard, Privacy Center, EU Withdrawal page. Their EU Withdrawal setup guide walks through slug, footer menu, email templates, and thank-you page.
Consentmo vs withdrawal-only apps
| Criteria | Consentmo | Narrow withdrawal apps | Cookie-first apps |
|---|---|---|---|
| Primary job | EU privacy, accessibility, withdrawal in one hub | Withdrawal only | Cookie banner first |
| Statutory wording | “Withdraw contract” / “Confirm withdrawal” built in | Varies | Often a secondary feature |
| Guest flow without login | Yes | Often yes | Inconsistent |
| GDPR / cookies in same product | Yes, core product | No | Yes |
| Audit log + CSV export | Yes | Some | Rare |
A cookie banner does not satisfy Article 11a. If a cookie app bundles “withdrawal,” check two-step flow, statutory labels, guest access, and confirmation emails before you trust the badge.
EU AI Act Article 50 from 2 August 2026
Withdrawal is live. The next date most marketing teams track under the EU AI Act is deployer transparency for AI visuals.
What deployers actually have to do
From 2 August 2026, if you publish AI-generated or materially AI-altered images or video that could pass for real (product pages, ads, realistic lifestyle scenes), shoppers need a clear visible label at first exposure. Hidden metadata and a policy page in the footer do not replace that.
| Role | Who | Duty |
|---|---|---|
| Provider | Midjourney, Firefly, ChatGPT, etc. | Machine-readable marking at creation (Art. 50(2)) |
| Deployer | You, the merchant publishing under your brand | Visible disclosure at first exposure (Art. 50(4)/(5)) |
Provider watermarks and C2PA metadata do not replace your deployer label. Shopify’s CDN often strips embedded file metadata on upload anyway. See our EU AI Act deployer FAQ for the full breakdown.
Which product images need labels
Label AI-generated product photos, synthetic studio scenes, real photos with AI background swaps or synthetic models, and realistic AI imagery in ads or emails that influence purchase decisions.
Skip minor retouching, clearly stylized illustrations, and abstract graphics no one would read as documentary photography.
Quick test: if a shopper could think “this is what it really looked like,” treat it as in scope under the EU AI Act.
Where EU AI Label fits
EU AI Label handles the deployer photo job a withdrawal form or cookie banner cannot:
-
Text-first overlays on product photos via theme app extension, no theme code edits
-
Bulk labeling when you import hundreds of AI shots
-
Compliance Hub and audit log so labeling is documented
-
Multilingual badges for EU storefronts
-
CoP-aligned presets (“AI-generated image”, “AI-altered photo”)
Free tier: 10 labeled photos. Starter €7/mo for 100 photos. Growth €15/mo for 500. See pricing.
For files that leave your store (social, PDFs, marketplace listings), use EU AI Icon to burn labels into the pixels. For site-wide coverage beyond product photos, AI Act Icon runs from a script tag. Toolkit map: aiact.solutions.
How the stack fits together
Consentmo covers consumer rights and privacy now: withdrawal button, two-step flow, email proof, cookies, accessibility. EU AI Label covers EU AI Act Article 50 on catalog imagery: visible labels, bulk tagging, Compliance Hub. EU AI Icon and AI Act Icon handle off-site creatives and non-catalog pages.
Agencies managing EU storefronts often bundle Consentmo setup with an AI photo audit and EU AI Label config in one onboarding sprint. Two deadlines, two deliverables, instead of one vague “EU compliance” project.
Setup checklist
Withdrawal (should already be live)
-
Confirm you sell to EU consumers and which markets you target.
-
Install Consentmo EU Withdrawal: page, footer link, emails, thank-you page.
-
Add Order Status entry on Enterprise if post-purchase flow is light on accounts.
-
Train support to review requests in the Consentmo log. Do not promise instant refunds on exempt SKUs.
-
Export a test CSV and archive it.
AI Act product photos (before 2 August 2026)
-
Audit catalog and campaign assets for AI-generated or materially AI-altered shots.
-
Sort: label needed, minor retouch only, or decorative art.
-
Install EU AI Label and set text-first badges per market.
-
Preview on mobile. Check contrast on white and dark backgrounds.
-
Publish Compliance Hub so teams share one source of truth.
-
Run the Shopify AI Act checklist with counsel sign-off.
FAQ
Is the withdrawal button mandatory if I’m outside the EU?
Usually yes, if you sell to EU consumers online. Headquarters location does not automatically exempt you.
Can Shopify returns settings replace a withdrawal button?
No. Returns tools help operationally, but the directive requires a customer-facing electronic withdrawal function with the characteristics above.
Does Consentmo replace EU AI Label?
No. Consentmo covers withdrawal and privacy. EU AI Label covers EU AI Act Article 50 labels on product imagery. Stores using AI product photos need both.
Do I need to label every AI image on my site?
No. Start with realistic imagery that could influence a purchase: product photos and ad creative. Decorative blog art is usually lower priority. See our FAQ on blog and IPTC myths.
I already have a withdrawal-only app
If it has statutory wording, guest access, two-step confirmation, and email proof, you may be fine. Check whether you still need a separate GDPR cookie tool. Moving to Consentmo often cuts app sprawl.
Fine exposure for Article 50 vs withdrawal?
Different regimes. EU AI Act transparency sits in the tier discussed as up to €15M or 3% of global turnover for other Act obligations. Withdrawal failures can trigger consumer-law fines (up to 4% of turnover in some states) and the 12-month extended withdrawal period.
Links
| Job | Start here |
|---|---|
| Withdrawal + GDPR | Consentmo EU Withdrawal |
| Label AI product photos | EU AI Label · checklist |
| Burned-in labels for ads, email, PDFs | EU AI Icon |
| Full toolkit | aiact.solutions |
| Agency programs | EU AI Label Partners |
Not legal advice. EU AI Label supports transparency and consumer-rights workflows; it does not guarantee legal compliance. Confirm withdrawal eligibility, product exemptions, and EU AI Act scope with counsel for your store, catalog, and markets.