Before putting an AI in front of your customers, three questions really matter: does it tell the truth about your products, what does it do with the data it collects, and who answers if it gets something wrong. A badly built AI can invent information — a tribunal has already held a company responsible for exactly that. In beauty the stakes are higher: bad advice about a pregnancy or an allergy costs dearly, in human and in legal terms. Making it reliable means framing the advice on a validated base, never stepping outside the catalogue, routing sensitive cases to a person every time, and keeping a record of every exchange. On data, the rule is minimisation: collect little, host in Europe, bind it by contract, delete it at the end. This content is informative: for your precise situation, speak to your adviser.
The 3 real questions before putting an AI in front of your customers
Before installing an AI on your store, ask yourself three questions, in this order: does it tell the truth about your products, what does it do with the data it collects, and who is responsible if it gets something wrong. Those three questions are enough to separate the serious tools from the improvised ones.
The first is about accuracy. A generative AI can, by construction, produce an answer that is plausible and wrong: an invented price, an ingredient that doesn't exist in your catalogue, a promise the product doesn't keep. That is what is called a hallucination.
The second is about data. A customer conversation often contains personal information, sometimes sensitive (skin, health, pregnancy). You need to know where it is hosted, whether it is shared with a third party, and how long it is kept.
The third is about responsibility. If the AI gives advice that causes a problem, on your site it is your brand that answers to the customer — not only the vendor of the tool. Which is why it is worth understanding, before installation, how an AI built to sell differs from a simple chatbot.
The risk of invention: what the Air Canada case showed
The risk of invention — hallucination — is real: a poorly framed AI can assert something false with exactly the same confidence as something true, and the company that runs it carries the consequences. One case became a reference in the sector: in 2024, a tribunal held Air Canada responsible for an answer invented by its automated service, which had promised a customer a refund the airline then refused to honour. The tribunal's finding was that the customer could reasonably rely on what the company's own tool told him.
That case was about a fare policy. In beauty, the stakes rise a level: bad advice is not about a refund but potentially about a contraindication in pregnancy, an allergy, or a skin reaction. An invented answer on that ground is not merely a commercial nuisance — it can affect the health of the person who trusted you.
That is why an AI advising on beauty products cannot work like a general-purpose chatbot. It needs a specific frame, which we set out in the AI advisor for beauty and skincare guide.
How you make AI beauty advice reliable
You make beauty advice reliable by building it on a register reviewed and approved by health professionals — a dermatologist, a paediatrician, a pharmacist — never on the AI model's improvisation. That is the difference between an AI that « chats » and an AI that advises inside a checked frame.
Three guardrails complete that register. First, the AI never recommends outside the retailer's catalogue: it cannot suggest a product or a brand that doesn't exist in your store. Second, on sensitive cases (pregnancy, allergy, a complaint) a fixed rule applies: it hands over to the retailer's team rather than answering in its place. Third, every conversation is on the record, so an exchange can be revisited if there is any doubt.
At Beautymarket, the number one beauty and skincare store in Morocco, the Ryma advisor went through 100,000 test conversations before going into production, on a catalogue that includes L'Oréal, La Roche-Posay, Vichy, Avène, Bioderma and CeraVe. That level of testing is what makes automated advice trustworthy on a subject as sensitive as skin. The full detail of that deployment is in the Beautymarket case.
GDPR in practice: what happens to your customers' data
GDPR applied to an advisory AI rests on a simple principle: collect only what is necessary, host it in Europe, anonymise it before any processing by the AI models, and delete it at the end of the contract. That is not an option — it is the condition for an advisory tool to be defensible in front of your customers and your regulator.
In practice that means: minimisation (you don't store a piece of data « in case » it becomes useful later), data hosted in Europe, exchanges anonymised before they reach the AI models, a signed data processing agreement with the vendor, and effective deletion at the end of the contract.
One point deserves particular attention in beauty: information about skin is sensitive data by nature — it touches health. The rule to apply is strict: collect the minimum, and never resell or share it for commercial purposes. A customer who describes her skin to an advisor does not expect that description to travel.
If you sell outside the European Union, the applicable regime may differ — this page describes GDPR because that is the framework Ryma is built on, not because it is the only one that can apply to you. For the technical side of setup, particularly on Shopify, see how to install an AI on a Shopify store.
Who is responsible for the advice shown on your site
You remain responsible for the advice shown on your site, even when an AI generates it: it is your brand, your customer relationship, and in the end your name on the line. Which is why the tool has to be built to leave you the wheel, not to take it away.
In practice that means a dashboard where your team keeps control at any moment, the ability to re-read what was said, and clear limits set up front (a closed catalogue, automatic escalation on sensitive cases). A tool that cannot be supervised, corrected or switched off on demand is not a tool a serious brand can lean on.
The right way to see it: the AI prepares the work, your team keeps the last word on the cases that need it. That is already the logic behind abandoned cart follow-up on WhatsApp, where every message stays on the record and under supervision.
The checklist of questions to put to any AI vendor
Before signing with an AI vendor for your store, ask these concrete questions. They are enough to tell a serious tool from one that improvises.
- Is the advice built on a base validated by health professionals, or on the AI model alone?
- Can the AI recommend a product that is not in my catalogue?
- Is there an automatic escalation rule to a human on sensitive subjects (pregnancy, allergy, complaints)?
- Where is my customers' data hosted, and is it anonymised before the AI models process it?
- Is a data processing agreement offered, and is the data deleted at the end of the contract?
- Do I get a dashboard to follow, correct or switch off the AI at any moment?
- Is every conversation recorded and readable in the event of a dispute?
- What concretely happens if the AI gets something wrong: who is told, and how quickly?
To understand the wider landscape before comparing offers, our e-commerce chatbot guide sets out the basics of the market.
Frequently asked questions
›Can an AI invent a product that doesn't exist in my store?
Yes. A poorly framed generative AI can invent a product, a price or a feature that doesn't exist — that is the risk of invention, or hallucination. It is why a serious advisory AI has to be built never to recommend outside your real catalogue. Check that point before any installation: it is the first line of defence against an invented answer.
›Who is responsible if the AI gives a customer bad advice?
You are. As the retailer you remain responsible for the advice shown on your site, even when an AI generates it. A tribunal already settled that point in 2024 in the Air Canada case, holding the company responsible for an answer invented by its automated tool. Which is why you need to keep the wheel through a dashboard, and to require systematic escalation on sensitive cases.
›Does my customer data leave the country with an advisory AI?
That depends entirely on the vendor. Require hosting in Europe, anonymisation before the AI models process anything, and a signed data processing agreement. Without those guarantees in writing, you cannot know where your customers' information actually travels. Ask the question explicitly before signing.
›Do I need a specific legal notice telling customers they are talking to an AI?
That is a compliance question that depends on your situation, your sector and your country, and it cannot be answered generally here. For your precise situation, speak to your legal adviser, who can check which obligations apply to your store.
›Can the AI be switched off at any moment if something goes wrong?
Yes, and it must be — it is a criterion to check before choosing a vendor. A well-built tool gives your team a dashboard to follow conversations, take over an exchange, and disable the AI immediately if needed. If a vendor cannot guarantee that control, treat it as a warning sign.
Alexandre builds Ryma, the AI-powered advisor for online stores, and writes these guides from real deployments, with every figure attributed.