EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Recommendation Engines and Personalisation AI

Most product, content and ad recommenders are minimal-risk under the EU AI Act, with Article 50 and Article 5 limits. Where recommenders become high-risk and what the DSA adds.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

Minimal risk

Minimal risk in most configurations; Article 50 and Article 5 limits; Annex III when used for listed purposes

When it applies

Article 5 applies since 2 February 2025; Article 50 since 2 August 2026.

Regulation (EU) 2024/1689, Art. 5(1)(a)-(b), Art. 50, Annex III; Digital Services Act Arts. 27 and 38

Recommendation systems are the most widely deployed AI in commerce and media, and most of them are minimal-risk under the EU AI Act. Product recommendations on a store, “next episode” suggestions, news feeds and ad targeting are not on the Annex III list. That does not mean no obligations: the manipulation bans in Article 5, the transparency duties in Article 50 where the recommender interacts with people or generates content, and the AI literacy duty all apply.

The picture changes when the recommender’s output is a decision about a person in a listed area. A recommender that decides which candidates a recruiter sees, which loan offer a person is eligible for, or which educational track a student is placed in is not a “recommender” for AI Act purposes; it is a high-risk system for that listed purpose.

Classification

Why this classification applies

The AI Act classifies by intended purpose, and “rank products or content by predicted relevance” is not among the Annex III purposes. The four risk tiers therefore leave ordinary recommenders in minimal risk, where the regulation encourages voluntary codes of conduct (Art. 95).

Article 5(1)(a) prohibits AI that deploys subliminal, manipulative or deceptive techniques to materially distort behaviour and cause significant harm, and 5(1)(b) prohibits exploiting vulnerabilities of age, disability or social or economic situation. A recommender optimised to exploit compulsive behaviour in minors, or to push high-interest credit at people flagged as financially distressed, is exposed under these bans.

For platforms, the Digital Services Act adds its own recommender rules: explain the main parameters in the terms, offer a non-profiling option on very large platforms, and let users change the parameters. Those duties are separate from the AI Act and already apply.

Obligations

What you have to do

  • Document the classification: intended purpose, why no Annex III entry applies, and the date of the review.
  • Check the design against Art. 5: no manipulative or deceptive techniques, no exploitation of vulnerable groups, with specific attention to minors.
  • If the system interacts conversationally or generates text, images or audio, apply the Art. 50 disclosure and labelling rules.
  • AI literacy for the teams that tune the recommender (Art. 4).
  • Platform operators: comply with DSA recommender transparency (Art. 27) and, for very large platforms, the non-profiling option (Art. 38).
  • Re-assess whenever the recommender starts to influence access to jobs, credit, education, insurance or essential services.

Paperwork

Documents to have on file

Classification memo
Art. 5 design review record
AI mention in Terms of Service and privacy policy
Internal AI usage policy and AI literacy record
DSA recommender transparency section in the terms (platforms)

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Treating job-board or marketplace ranking as “just a recommender”. Ranking candidates or targeting job ads is Annex III(4)(a).
  • Personalising credit or insurance offers by predicted risk. That is creditworthiness evaluation or insurance risk assessment under Annex III(5).
  • Engagement optimisation aimed at children without safeguards. This is the exact scenario the Art. 5(1)(b) vulnerability ban describes.
  • Ignoring the DSA because the AI Act says minimal-risk. They are separate laws with separate duties.

FAQ

Frequently asked questions

Do we have to tell users that recommendations are AI-generated?

Article 50(1) is about systems that interact with people, so a silent ranking does not require a disclosure by itself. Best practice, and often a DSA requirement for platforms, is to explain in the terms that recommendations are automated and what drives them.

Is ad targeting regulated by the AI Act?

General ad targeting is minimal-risk. Targeting job advertisements is expressly high-risk (Annex III(4)(a)), and targeting based on inferred sensitive characteristics can breach Art. 5(1)(g) and GDPR.

What happens if we later add a loan-offer feature?

The system, or that component, becomes high-risk for that purpose and the full set of obligations applies before the feature goes live. Re-run the assessment whenever the purpose changes.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-22. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.

Related use cases

Limited risk

Customer service chatbots

Read →

Limited risk

Generative AI content & deepfakes

Read →

High-risk

Credit scoring & lending

Read →

Guide

EU AI Act compliance guide

Read →