Back to Blog
Table of contents
Request a Custom Free Sample
Book a call with our creative team and receive a custom visual sample with your garments within 48 hours. Free, no commitment.
GET YOUR FREE SAMPLE

The EU AI Act and AI-Generated Product Images: What Ecommerce Brands Need to Know

Article 50 of the EU AI Act requires disclosure for AI-generated and AI-manipulated product images. Here's what needs labeling, and what doesn't.
Ioanna Nella
Updated on:
July 31, 2026

The EU AI Act sorts artificial intelligence systems into risk tiers, from prohibited practices at one end to minimal-risk tools at the other. Most of what ecommerce teams actually use, including AI photo editing and AI-generated product imagery, sits outside the heavily regulated high-risk category.

That doesn't mean it sits outside the Act entirely. A separate set of rules, the transparency obligations in Article 50, apply regardless of risk tier whenever AI creates or manipulates image, audio, or video content. Those rules took effect on 2 August 2026, and they're the part of the Act that touches your product photos, campaign imagery, and virtual models.

This piece focuses on that slice: what Article 50 requires for AI-generated and AI-retouched ecommerce imagery, what it doesn't cover, and what to do about it. It isn't a full walkthrough of the AI Act, which also governs chatbots, biometric systems, and high-risk AI used in areas like credit scoring or recruitment.

What Article 50 requires for image content

Article 50 splits the obligation in a way that matters for who's responsible. Providers of AI systems that generate synthetic image, audio, or video content, the companies building the AI tools themselves, have to make sure their outputs are marked in a machine-readable format and detectable as artificially generated. That's a technical requirement on tools like Midjourney or Nano Banana, not something an ecommerce brand implements directly.

The obligation that lands on a brand is different. As a deployer, meaning the business using the AI system rather than building it, you're responsible for disclosing when content you publish qualifies as a deepfake under the Act's definition: AI-generated or manipulated image, audio, or video content that resembles an existing person, object, place, entity, or event and would falsely appear authentic to a viewer. That disclosure has to reach the person seeing the content, in a clear and distinguishable way, no later than the moment they first encounter it.

The practical question for most ecommerce teams isn't whether Article 50 applies to their business. It does, the moment any AI-generated or AI-manipulated image goes in front of an EU customer. The real question is which images in a typical catalog meet the deepfake definition, and that's less obvious than it sounds.

Does this apply to routine retouching, or only AI-generated imagery?

Most of the confusion sits here, and the answer depends on what the AI changed, not on whether AI touched the image at all.

Article 50(2) carves out an exemption for AI that performs an assistive function for standard editing, or that doesn't substantially alter the input data or its meaning. Ordinary color correction, background cleanup, minor lighting adjustments, and resizing generally fall into that category. The Commission's draft guidance on the transparency rules, reported by Bird & Bird's analysis of the guidelines, treats these kinds of edits as outside the deepfake definition because they don't create a false impression that something happened that didn't.

AI-generated people are a different case. The Commission's guidance reads the deepfake definition's reference to "existing persons" broadly: a subject only has to resemble someone who could plausibly exist, not a specific named individual. That means a fully synthetic AI fashion model, generated with no real person as a reference, can still trigger the disclosure requirement if it looks like a real person could have worn the garment in a real photo. Advertising and commercial content don't get the lighter disclosure treatment reserved for evidently artistic or fictional work. In my reading of the guidance, that bar is lower than most creative teams assume: I'd treat any photorealistic synthetic model as inside the disclosure requirement by default, since the guidance leaves very little room to argue otherwise.

The line that matters is whether the image still reads as documentation of something that happened, or whether it introduces a person, scene, or moment that never existed. Routine retouching on a real photo of a real product stays on the safe side of that line. A synthetic model in an AI-generated lifestyle scene usually does not.

Whether an image needs an AI disclosure label depends on what the AI actually changed, not whether AI was involved at all.

Labeling in practice

Once you've determined an image needs disclosure, the next question is how to label it. Article 50 requires disclosure to be clear, distinguishable, and delivered no later than first exposure, but it doesn't mandate a specific format. The Commission filled that gap with a practical tool.

On 10 June 2026, the Commission published a set of free icons for labeling AI-generated content, available in SVG and PNG, as part of the Code of Practice on marking and labelling of AI-generated content. There are three variants: a basic icon for content involving AI-generated deepfakes, a "Fully AI-Generated" icon for content with no human-created elements beyond prompting, and a "Partially AI-Modified" icon for existing human-made content altered into a deepfake. Each comes in four color treatments, and none require attribution to the Commission or the AI Office to use.

Use of the icons is optional. The disclosure requirement under Article 50 is not. Applying an icon doesn't automatically satisfy the law on its own, and the Commission is explicit that deployers remain responsible for making sure their disclosure actually meets the Article 50 standard, icon or no icon.

A few placement rules matter in practice. The label needs to be visible at first exposure, without anything overlaying it, and it needs to stay attached to the content if it's reshared or downloaded. The Commission's own testing found that pairing the icon with a short plain-language label, something like "modified," performed better than the icon alone. For an ecommerce PDP or lookbook image, that likely means the label sits on or immediately next to the image itself, not buried in a footer disclaimer or a separate policy page.

What this doesn't cover

Article 50 handles disclosure. It doesn't answer two other questions that come up constantly with AI-generated ecommerce imagery: who owns the image, and whether a synthetic model creates legal exposure around a real person's likeness.

On ownership, EU copyright law doesn't have an AI-specific rule, and the European Parliament's own briefing on the topic confirms the gap: current CJEU case law and Member State practice both point toward requiring human creativity for copyright protection. Content generated purely by an AI system, with no meaningful human authorship, is unlikely to be copyrightable in the EU. Content that combines AI generation with real human creative input, such as a photographer's original composition later enhanced or extended with AI, sits in more protected territory, though the line is still developing case by case.

On likeness, the picture is more fragmented because the AI Act itself doesn't govern right-of-publicity or personality rights. Those run through national law and, where personal data is involved, GDPR. The practical risk shows up when a fully synthetic model happens to resemble an identifiable real person, whether a public figure or someone whose photo was part of a training set, since that can trigger a personality-rights claim independent of anything Article 50 requires. A synthetic model with no resemblance to any real individual carries substantially lower risk on this front, though it may still need the deepfake disclosure covered above.

Neither of these areas is settled enough to treat as fixed. If a specific image, campaign, or model raises a real ownership or likeness question, that's worth a conversation with counsel rather than a general rule from an article like this one.

Penalties, briefly

Article 50 breaches don't fall under the Act's headline penalty figure. The €35 million or 7% of global turnover tier is reserved for violations of Article 5's prohibited practices, things like manipulative AI or unauthorized biometric categorization, not transparency failures.

Transparency obligations under Article 50 sit in the second tier of Article 99's penalty structure: fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Regulators are also required to weigh the nature and duration of the infringement, how many people were affected, and whether the business cooperated once the issue surfaced, so the maximum figure is a ceiling, not a default outcome. SMEs and start-ups get the lower of the two figures rather than the higher, a protection built directly into the Article.

This sits alongside the disclosure requirement, not instead of it. The enforcement structure exists to give Article 50 actual weight.

What ecommerce teams should do now

This doesn't call for an overhaul so much as an honest inventory of what's running through your imagery pipeline, since Article 50 is already in effect.

I'd start with an inventory, not a policy. Go through your active campaigns and product catalog and separate images into three groups: real photography with standard retouching, real photography enhanced or manipulated with AI in ways that go beyond assistive editing, and fully AI-generated content, including synthetic models and generated backgrounds. The first group is unlikely to need disclosure. The second and third need the deepfake test above applied image by image, not campaign by campaign, since a single lookbook can mix all three.

For anything that lands on the disclosure side of that line, I'd decide on a labeling approach before the next campaign ships, not after. That means picking where the label sits, ideally on the image itself rather than a buried policy page, what text accompanies it, and who signs off before publication. Documenting that decision matters beyond compliance theater: Article 99 explicitly lists cooperation and the operator's own organizational measures as factors that reduce penalty exposure if something does go wrong later. A written visual style guide that covers when and how AI is used in your imagery, alongside the usual specs on color, cropping, and framing, gives your team and any outsourcing partner a single reference point for this instead of relying on ad hoc judgment calls per shoot.

Where a specific image raises a genuine question, an unusually realistic synthetic model, a scene that reads as documentary rather than obviously staged, treat it as a legal question rather than a creative one. My rule of thumb: if you're debating whether an image needs a label, treat the debate itself as the answer and label it. The cost of a quick review is small next to the cost of guessing wrong on a customer-facing image at scale.

Share:

FAQ

Does the EU AI Act require me to label every AI-edited product photo?

No. Routine editing, color correction, background cleanup, resizing, doesn't trigger the disclosure requirement. Labeling applies specifically to content that meets the Act's deepfake definition: AI-generated or manipulated imagery that resembles a real or plausible person, object, place, or event and could pass as authentic.

Does this apply to my brand if we're not based in the EU?

Yes, if the imagery reaches EU customers. Article 50 applies based on where the content is seen, not where the business is headquartered.

Can a fully synthetic AI model avoid the deepfake rule since it isn't based on a real person?

Not necessarily. The Commission's guidance reads "existing persons" broadly enough to cover a realistic synthetic person who could plausibly exist, not only lookalikes of named individuals.

What happens if we don't comply?

Article 50 breaches fall under a penalty tier of up to €15 million or 3% of global annual turnover, whichever is higher, distinct from the higher 7% tier reserved for prohibited AI practices.

Do we have to use the EU's official AI-content icons?

No, they're optional. The underlying disclosure obligation is not.

Related articles

Ready to scale your brand’s visual identity?

Book a call with our creative team and receive a custom sample with your garments within 48 hours. Free, no commitment.