CXO Ready

    Retail

    Retail adopted AI faster than it governed it.

    Retail runs more customer-facing AI than almost any sector, much of it bought as a feature rather than built as a system. CXO Ready puts the whole estate in one register and shows which parts carry real regulatory weight.

    The AI you are probably already running

    Most of these arrive as a feature of something you bought rather than as a project anyone called AI. That is exactly why they are missing from the register.

    • Dynamic and personalised pricingWhere fairness questions arrive fastest, particularly if prices vary by inferred characteristics rather than by market conditions.
    • Recommendation and ranking enginesUsually the earliest AI in a retail estate, and often the least documented.
    • Demand forecasting and allocationLower regulatory exposure, high commercial dependence. Worth governing because the business now relies on it.
    • Loss prevention and facial recognitionBiometric identification carries the heaviest obligations of anything in a retail estate, and the closest regulatory attention.
    • Customer service assistantsHandling returns, complaints and product questions, sometimes making decisions with contractual effect.
    • Seasonal recruitment screeningRetail hires at volume, and employment screening is a named high-risk use under the EU AI Act.
    • Workforce scheduling and productivityAlgorithmic management of staff is drawing increasing scrutiny across Europe.

    Volume, and a public that notices

    Retail AI touches more people, more often, than in almost any other sector, and it does so in public. A pricing model behaving oddly is a news story rather than an internal incident, and reputational damage arrives long before regulatory action does.

    The estate is also unusually federated. Marketing bought a personalisation engine, operations bought forecasting, loss prevention bought something with a camera, and HR bought screening — often without a shared record. That is not a failure of process so much as a consequence of how retail technology gets purchased, and it is why discovery matters more here than governance frameworks do.

    What you get

    One register across a federated estate

    Marketing, operations, loss prevention and HR systems in the same place — usually the first time anyone has seen the whole picture, because no single procurement record contains it.

    Vendor and data source mapping

    Which third party sits behind each system and what data flows into it, so a vendor question becomes a scoped list rather than a week of discovery.

    Data types recorded per system

    Including biometric and personal data, so the systems carrying the heaviest obligations stand out from the forecasting models.

    Human oversight and explainability

    Recorded per system: what drives the decision and who can overrule it — the question you need answered before anyone asks how a price or a flag was set.

    EU AI Act classification per system

    Each system classified by what it is used for, with the reasoning stored alongside it, so employment screening and customer-facing tools are triaged properly.

    Adoption and ROI per system

    Cost to deliver, running cost and adoption tracked against the objective each system was meant to serve.

    What changes

    A federated estate, in one register

    Marketing, operations, loss prevention and HR systems in the same place, which is usually the first time anyone has seen the full picture.

    Biometric systems separated out

    Anything touching biometric data flagged as the distinct regulatory problem it is, rather than sitting in a list beside a forecasting model.

    Explainability where customers are affected

    Recorded per system: what drives the decision, who can overrule it, and what a customer would be told if they asked.

    Evidence before the questions arrive

    Which matters in a sector where the first question often comes from a journalist rather than a regulator.

    CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Before you start

    Questions from retail

    How does CXO Ready handle biometric systems differently?

    It records the data types each system uses, so anything touching biometric data is visibly separated from the forecasting and personalisation models. Lawful basis, DPIA status and human oversight are captured against those systems specifically, which is what you need in front of you before deciding whether a deployment is justified.

    Does personalised pricing count as high-risk AI?

    Not in itself under the EU AI Act, which does not list it in Annex III. The exposure is elsewhere: consumer fairness, and whether pricing varies by characteristics that would be discriminatory if stated openly. The governance question is whether you can explain what drove an individual price — and most retailers currently cannot.

    How do we find AI bought by individual departments?

    Surveys, framed as amnesty rather than audit. Retail estates are federated by nature, so no central procurement record will show you everything. Ask teams what they use and what it does, and expect to find several systems nobody at the centre knew about — that is the normal result, not a sign of a badly run business.

    Our AI is all vendor-supplied. Are they not responsible?

    Not for your use of it. A vendor may be the provider under the EU AI Act while you are the deployer, and deployers carry their own obligations around human oversight, monitoring and informing affected people. You also cannot delegate the UK GDPR accountability for decisions made about your customers.

    Where should a retailer start?

    With the customer-facing systems and anything involving biometrics or employment screening. Those carry the heaviest obligations and the highest reputational exposure. Forecasting and supply chain models matter commercially but are rarely where the regulatory risk sits, so they can follow.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy