A virtual try-on previews colour or finish. A recommendation system can narrow a catalogue using stated preferences. Neither can prove that a product is safe for a person, diagnose a skin condition or guarantee how a cosmetic will perform outside the captured image.
This beauty-retail guide, published in December 2025, is current through 31 July 2026. Cosmetic-product rules differ between Great Britain and Northern Ireland under the Windsor Framework. Medical-device and medicines routes also have jurisdiction-specific details. Businesses should determine the product, claim, market and intended purpose before launching an AI experience.
Separate the experience into distinct claims
“AI skincare analysis” can hide several different functions. Name the function a customer actually receives and the evidence behind it.
| Function | Appropriate output | Boundary |
|---|---|---|
| Colour try-on | Visual approximation of shade or finish | Not a guaranteed physical result |
| Product filter | Items matching stated preferences | No diagnosis or hidden health inference |
| Routine builder | Order of compatible catalogue items | Safety instructions and product limits remain |
| Image description | Visible cosmetic features under stated conditions | No disease label |
| Support triage | Route a concern to trained staff | Urgent or medical concerns leave the sales flow |
| Clinical-purpose software | Output for diagnosis or treatment | Assess medical-device route before release |
Write the intended purpose, user, input, output and prohibited interpretation. The interface, advertisements and generated language must match that statement. A disclaimer at the bottom cannot repair a journey that repeatedly calls a sales recommendation a diagnosis.
For the broader use of AI across cosmetic retail and wellness, see our beauty and skincare AI guide.
Keep the regulated product record authoritative
The Office for Product Safety and Standards’ guidance on making cosmetic products available in Great Britain explains the Responsible Person, product safety report, Product Information File, notification, labelling and claim obligations. Every cosmetic offered by the recommender should resolve to that controlled product record.
The catalogue needs:
- product and shade identifier;
- Responsible Person and market;
- current ingredient list;
- warnings and instructions;
- batch or version relationship;
- approved purpose and claim wording;
- evidence reference and owner;
- availability and market;
- adverse-event and complaint route;
- withdrawal or recall status.
Do not let a model invent an ingredient, concentration, warning or compatibility statement. Retrieve the approved field and show it unchanged. If the record is missing, stale or unavailable, remove the recommendation until it is resolved.
Before a cosmetic is made available in Great Britain, the Responsible Person must notify OPSS. The Submit Cosmetic Product Notifications service is the official route; a recommendation-platform listing does not replace it.
Northern Ireland follows a different route. The government’s guidance on cosmetic products in Northern Ireland explains the Responsible Person, notification and Windsor Framework position. Build market eligibility into the product service rather than asking generated copy to remember it.
Keep cosmetics, medicines and devices distinct
A cosmetic primarily cleans, perfumes, changes appearance, protects, keeps in good condition or corrects body odour. Claims to diagnose, prevent or treat disease can move the product or software into another regulatory category.
The MHRA’s July 2026 guidance on borderline products and medicines explains that claims, mode of action, intended purpose and overall presentation matter. The MHRA also provides current material on software and AI as a medical device.
Escalate regulatory review before using outputs such as:
- diagnosis of acne, eczema, rosacea or another condition;
- probability of disease or treatment need;
- a claim that a cosmetic treats or prevents disease;
- a recommendation presented as a substitute for medical care;
- a risk score that determines clinical referral;
- analysis of a changing lesion or urgent symptom.
The MHRA’s medical-device software-app guidance helps determine when an app may be a medical device. Intended purpose cannot be narrowed by a disclaimer if the interface, model and advertising imply a medical function.
Create a visible route for customers to stop and seek an appropriate healthcare professional when they report pain, rapid change, bleeding, severe reaction or another concern outside cosmetic support. Do not use that moment to intensify product sales.
Make virtual try-on an honest simulation
A face preview depends on camera, lighting, white balance, screen, pose, occlusion, skin reflectance and rendering. It may not show texture, wear, irritation, oxidation or interaction with an existing product.
Test the full experience:
- different skin tones and undertones;
- varied lighting and camera quality;
- glasses, facial hair and head coverings;
- different face shapes and ages;
- low bandwidth and older devices;
- supported operating systems and browsers;
- products with gloss, shimmer or translucence;
- single and multiple faces in frame;
- partial faces and motion;
- image upload, live camera and no-camera alternatives.
Measure landmark failure, shade-display error and unacceptable rendering by cohort and device. Ask users whether the preview helps them compare, without treating subjective preference as colour accuracy.
Show a plain statement that the image is a simulation. Keep the original product swatch, ingredients, warnings, size and return terms accessible. Let the customer turn the camera off and browse the same range.
The ASA’s guidance on before-and-after photographs explains that images can make objective efficacy claims and must not exaggerate likely results. A generated or retouched “after” image is especially risky when it depicts an effect the cosmetic cannot substantiate.
Govern recommendation quality and conflicts
Define the recommendation objective. “Best product” is not meaningful if the ranking actually optimises margin, stock or sponsorship. Tell customers when a placement is paid or commercially influenced.
Use explicit preference fields where possible:
- desired colour family or finish;
- texture and fragrance preference;
- budget;
- stated sensitivity or ingredient avoidance;
- vegan or other product attribute based on verified catalogue data;
- delivery and availability.
Do not infer ethnicity, health, pregnancy or emotional vulnerability from a face to personalise sales. A skin image can reveal more than the customer intended. Avoid generating a persistent “skin age” or attractiveness score; it creates body-image and fairness risks without being necessary to compare products.
Evaluate relevance with blinded review and real customer testing. Examine whether products disappear for certain skin tones because catalogue imagery or historical sales are sparse. Exposure should not depend only on past conversion, which can reproduce earlier range and marketing gaps.
The CMA’s report on agentic AI and consumers warns that AI may steer people toward products that are more profitable but less suited to their needs. Keep recommendation criteria, paid placement and alternatives visible.
Our UK AI privacy guide covers the wider rights framework.
Treat face images as sensitive personal information
A photograph is personal data when a person is identifiable. It is not automatically special-category biometric data. The ICO’s biometric recognition guidance explains that specific technical processing for unique identification creates biometric data and, when used to uniquely identify someone, special-category biometric data.
A try-on tool normally does not need to identify a face. Do not enrol templates, compare against a customer database or reuse facial geometry for identity, fraud or advertising without a separate, documented purpose and legal assessment.
Apply privacy by design:
- process on-device where practical;
- collect one frame rather than continuous video where that meets the purpose;
- do not retain an image by default;
- separate try-on from account identity;
- provide a no-camera route;
- disclose model provider and data location;
- block provider training on customer images unless specifically justified;
- set and enforce deletion;
- restrict staff and support access;
- protect rights requests and withdrawal.
Complete a data-protection impact assessment where processing is likely to create high risk, especially with children, biometric recognition or health inference. Test whether consent is specific and freely given rather than bundled into checkout. Camera permission from the operating system is not the whole privacy notice or lawful-basis analysis.
Substantiate every generated claim
The OPSS GB guidance requires a Responsible Person to be able to prove cosmetic marketing claims. The ASA’s current Beauty and Cosmetics: General guidance explains the distinction between temporary cosmetic effects, cumulative claims and physiological claims, and warns against exaggerated retouching.
Build a claim library with:
- exact wording and permitted variations;
- product and market;
- evidence type and source;
- population and use conditions;
- qualifying text;
- effective and expiry dates;
- reviewer and approval;
- prohibited medical implication.
Generate only inside that library. A model should not turn “appearance of fine lines” into “reverses ageing,” or “helps keep skin in good condition” into “treats acne.” Testimonials and review summaries require provenance and balanced treatment.
Claims implied by an image count. Smoothing texture, changing pigmentation or removing a blemish in a try-on can suggest efficacy even when the product is colour cosmetics. Keep rendering changes limited to the product effect being simulated and retain test screenshots.
The ASA’s December 2025 guidance on cosmetic devices and medicinal claims demonstrates how claims about acne treatment can engage medical-device requirements. Review product, software and advertising together.
Secure the beauty-data supply chain
The experience may include camera SDKs, computer-vision models, analytics, ecommerce, loyalty, reviews and customer service. List each recipient and capability.
Minimum controls include:
- least-privilege service accounts;
- encryption in transit and at rest;
- short-lived upload URLs;
- malware and file-type validation;
- isolation of customer images from development datasets;
- logs for administrative access and exports;
- model and SDK update review;
- deletion across backups and subprocessors;
- vulnerability and incident notification;
- tested fallback and provider exit.
Treat image metadata and uploaded filenames as untrusted. Strip geolocation where it is not needed. Prevent instructions hidden in uploads or product content from changing catalogue, price or tool permissions.
Support teams should not download face images to personal devices or paste them into another model. Provide a controlled diagnostic view, automatic redaction where appropriate and a deletion workflow.
Use 90 days to prove a narrow benefit
Days 1–30: define and prepare. Choose one function, such as lipstick shade preview, without skin diagnosis or identity. Map GB and NI product eligibility, claims, camera data, suppliers and customer routes. Build a representative image-and-device test plan with consented or synthetic material. Establish catalogue and return baselines without promising reduction.
Days 31–60: shadow and test. Run the renderer in a test environment. Review failures across skin tones, devices, lighting and accessibility needs. Verify every displayed product field and claim. Complete privacy and security testing, including deletion, unauthorised access and supplier outage. Conduct user research on clarity and usefulness.
Days 61–90: release gradually. Offer the tool to a small audience with a no-camera alternative and clear simulation notice. Keep recommendations constrained to verified catalogue attributes. Monitor render failures, corrections, complaints, group differences, image retention and product-safety escalations. Review weekly with product, regulatory, privacy, security and inclusion owners.
At day 90, decide whether to expand the product range or improve the current experience. Do not add diagnosis, facial identity or health inference as an automatic next step; each is a new use case.
Define beauty pause gates
Disable the affected feature when:
- a product lacks a current safety, market or Responsible Person record;
- the system invents an ingredient, warning, compatibility or claim;
- rendering materially changes skin beyond the simulated cosmetic;
- errors are concentrated by skin tone, device or another relevant cohort;
- medical conditions are diagnosed or treatment is recommended outside the approved route;
- customer images are retained, trained on or shared unexpectedly;
- biometric identification or sensitive inference appears outside scope;
- a model, camera SDK or catalogue change invalidates testing;
- paid placement is presented as neutral suitability;
- no accountable person can manage a safety report or urgent escalation.
The fallback removes camera and AI output while leaving the verified catalogue, ingredients, warnings, contact route and ordinary shopping journey available. Preserve evidence needed to investigate, delete unrelated images and correct affected claims.
Beauty technology can make comparison more accessible and enjoyable. Trust comes from an honest simulation, verified product data, inclusive evaluation and a firm line between cosmetic retail and healthcare. The strongest recommendation is not the most personal one; it is the one whose purpose, evidence and data use a customer can understand.



