Since 2 August 2026, anyone who uses an AI system professionally to generate or manipulate image, video or audio content that is a deep fake must disclose that the content is artificial (Article 50(4) EU AI Act). An online retailer is such a deployer when it, or a contractor working to its instructions, uses AI to create product or advertising images (Commission guidelines, paras. 12 and 14).
The disclosure has to be clear, distinguishable and accessible, and it has to be there no later than the moment someone first sees the image (Article 50(5)). Deployers get no transition period. Images generated before the start date do not need to be labelled retroactively under the guidelines (para. 154).
Key facts
- The legal basis is Article 50(4) and (5) of Regulation (EU) 2024/1689, the EU AI Act. The provision has applied since 2 August 2026 (Article 113).
- The duty falls on the deployer, meaning whoever decides to use the AI system and how. Technical control over the tool is not required (guidelines, para. 12).
- A deep fake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. Consumer goods are expressly covered as objects (Article 3(60), para. 113).
- AI-generated text is only covered when it is published to inform the public on matters of public interest. Product descriptions and advertising copy generally fall outside the duty under the guidelines (examples to para. 131).
- A notice that only appears in terms and conditions, menus or an information page is not enough (para. 142). The machine-readable marking added by the AI provider does not replace a visible label (para. 117).
- Fines can reach EUR 15 million or 3 % of worldwide annual turnover, whichever is higher; for SMEs the lower amount applies (Article 99(4) and (6)). In Germany the Federal Network Agency (Bundesnetzagentur) enforces the rules.
The legal text
The obligation sits in two paragraphs of Article 50. Paragraph 4 sets out what must be disclosed. Paragraph 5 sets out how and when.
“Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.”
Article 50(4), first subparagraph, Regulation (EU) 2024/1689
“The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.”
Article 50(5), Regulation (EU) 2024/1689
“Distinguishable” carries real weight: the information has to be easy to identify as separate from other information and from the environment in which the content is shown (para. 142). A well worded notice that blends into the page does not pass. “Exposure” is the moment a person actually gets to see the content.
Who has to label: provider or deployer
Article 50 splits the duties between two roles. A provider develops an AI system and places it on the market, such as the company behind an image generator. Providers must mark the output of their systems as artificial in a machine-readable format (Article 50(2)). A deployer uses an AI system under its authority (Article 3(4)) and must disclose deep fakes visibly (Article 50(4)). The two duties apply side by side (para. 111).
The guidelines read “authority” as the decision to use a system and the decision on how to use it, including its output. Technical control over the tool is not needed (para. 12). Employees who act on instructions are not separate deployers; the company remains the deployer (para. 14).
The retailer as deployer
A store that uses an image generator, a generative fill tool or the AI feature of its e-commerce platform to create or edit product images is a deployer. The only exclusion is purely personal, non-professional use (Article 2(10)). Any activity through which someone regularly gains an economic benefit counts as professional (para. 19), so an online store never falls under the exclusion.
Agencies, photographers and freelancers
If a contractor works to your instructions, and you wanted, specified or approved the use of AI, you remain the deployer. The guidelines say a company stays the deployer when it involves contractors or freelancers who operate the system on its behalf and under its responsibility (para. 14).
The picture changes when you simply commission an advertising agency and take no decision on whether and how it uses AI. In that case the guidelines say you are not the deployer (para. 14); the agency is. It should take proportionate steps so that its label reaches the audience, for example through contractual terms with the partners that distribute the image (para. 12). You can ask for that label in your contract.
Images from manufacturers and suppliers
If you only pass on a manufacturer's AI image and had no say in the use of AI, you are generally not a deployer under the guidelines (para. 16). The guidelines nevertheless strongly encourage you to keep existing labels intact, and they encourage everyone who professionally disseminates content to inform the audience (paras. 16 and 17). Edit a supplier image with AI yourself and you become the deployer for that edit. Consumer protection law applies regardless: an image that shows a product as better than it is can be misleading, whoever created it.
Retailers outside the EU
Businesses established outside the EU are covered when they foresee that their AI output will be used in the Union, for instance through a store that sells into the EU (Article 2(1)(c); para. 13). Other countries' rules are covered under Worldwide.
What has to be labelled
The first subparagraph of Article 50(4) covers image, audio and video content that constitutes a deep fake. Article 3(60) defines it as AI-generated or manipulated content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
Three points from the guidelines decide most store cases:
- Products are objects. “Objects” expressly include consumer goods (para. 113 iii), so the product itself can be the subject of a deep fake.
- Nothing real needs to be copied. It is enough that the person, object, place or scene could plausibly exist (para. 113 ii). An invented but photorealistic AI model is covered.
- Intent does not matter. The assessment is objective and does not require any intention to deceive (para. 114). What counts is the full range of the foreseeable audience, including children, older people and people with little experience of AI (para. 115).
The guidelines use a product image as one of their examples of a deep fake: an AI-generated image of a product in advertising or on packaging that can affect perception and mislead about the product's actual appearance, characteristics or use, for example by making it look more appealing or of higher quality than in real life (examples after para. 116).
Text only on matters of public interest
“Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated.”
Article 50(4), second subparagraph, first sentence
Matters of public interest include politics, public administration, justice, fundamental rights, public security, public health, environmental protection and consumer safety (para. 131 iii). The guidelines list AI text in a company's advertising or product descriptions as outside the scope, unless it contains claims related to health, consumer safety or sustainability (examples to para. 131). A blog post on how diets affect a disease can be covered. The duty does not apply when a human reviews the text before publication and someone holds editorial responsibility; a spell check alone is not a review (Article 50(4), second subparagraph; paras. 134 and 135).
Chatbots: a separate duty
A chatbot in your store falls under Article 50(1), not paragraph 4. That duty is on the provider, who must design the system so that people learn they are talking to an AI (para. 31). A company that builds a chatbot in-house and runs it under its own name can be a provider itself (para. 11).
When the obligation started
Article 50 has applied since 2 August 2026 (Article 113; para. 153). Deployers get no transition period. The Digital Omnibus, Regulation (EU) 2026/1744, gave a grace period to providers only: generative systems placed on the market before 2 August 2026 must meet the machine-readable marking duty of paragraph 2 by 2 December 2026 (Article 111(4)). The guidelines call this a targeted grandfathering rule for paragraph 2 alone (para. 153).
One practical consequence: until December 2026, AI images can lawfully reach you without provenance data. Missing metadata therefore does not show that an image was made without AI.
Images created before the start date
Deep fakes generated or manipulated before 2 August 2026 do not need to be labelled retroactively (para. 154). The guidelines still encourage labelling, without expecting disproportionate effort such as auditing whole image libraries or changing packaging that has already been printed. For images, the date of the AI edit counts, not the date of publication. If an old image is edited with AI again after the start date, the new output is covered. Whether reusing an old deep fake in a new campaign triggers the duty is not settled. The wording of the guidelines suggests it does not, but labelling is the sensible choice. All dates are collected under Deadlines.
How the disclosure must be made
Article 50(5) sets four requirements, which the guidelines spell out:
- Clear: noticeable, easy to understand and accessible, including for people with disabilities (para. 142).
- Distinguishable: easy to identify as separate from other information and from the environment in which the image appears (para. 142).
- No later than first exposure: for each output and each person, at any moment someone is reasonably likely to see the image. The guidelines give scrolling through social media as an example (para. 143). In a store, first exposure is often the product card in a collection or in search results, not the product page.
- Accessible: in line with the accessibility rules that already apply. Article 50 does not add requirements of its own (para. 144).
Information that is easy to overlook under normal conditions does not count, for example a notice tucked into a manual, buried in menus or placed in terms of use (para. 142). Nor can deployers rely on the machine-readable marking the AI provider writes into the file, because people cannot perceive it without technical tools (para. 117).
The Commission's Code of Practice describes what the label should look like: the acronym “AI” as the main element, visible at once without a click, in a place free of overlapping elements, such as the top right corner (Code, Section 2, Measures 1.1 and 1.2). The Commission offers three free EU icons for this. Size, position, contrast and wording are covered in AI label design.
Exceptions
Standard editing and minor changes
Not every AI edit turns a photo into a deep fake. Under the guidelines, changes to insignificant aspects of existing content have little bearing on whether people perceive it as authentic (para. 116): colour correction, lighting adjustments, noise reduction or removing passers-by, for example. For advertising, the guidelines name extending or replacing a background for clearly aesthetic purposes, arranging existing products and rescaling. Context still matters (para. 116). Once the AI changes the product itself, or creates a scene that can mislead about size, function or effect, the exception no longer helps.
Evidently artistic works
If a deep fake is part of an evidently artistic, creative, satirical or fictional work, a disclosure that does not hamper the enjoyment of the work is enough (Article 50(4), first subparagraph, third sentence). A disclosure is still required (para. 123). The guidelines read “evidently” narrowly. Content that is recognisably purely informative or commercial is excluded, and where content mixes both, the informative character prevails (para. 122). Their counter-examples include a teleshopping style video with simulated consumers and a synthetic influencer testing a sponsored product (examples after para. 124). Product and advertising images will rarely benefit. An art print you sell as a work may be a different matter. The third exception, for uses authorised by law to fight crime, does not concern online stores.
Typical store cases: label or not
The table sums up how the guidelines treat common situations. It is not a substitute for looking at each image. The labelling check asks the guideline questions image by image and cites the paragraph behind each result. Worked examples are collected under Cases.
| Situation | Assessment | Source |
|---|---|---|
| Photorealistic AI model wearing your product | Label | Para. 113 ii, iii; examples after paras. 116 and 124 |
| Whole image generated with AI, photorealistic (product, lifestyle, room) | Label | Paras. 113 ii, 114; example after para. 116 |
| AI shows the product differently, nicer or of higher quality than it is | Label The image may also be misleading. | Example after para. 116; para. 129 |
| Colour variant created with AI from a photo of another colour | Label At least recommended, even if the colour matches. | Para. 113 iv; example after para. 116 |
| AI scene showing the product in use, with a size comparison or an effect | Label if the scene can mislead about size, function or effect; otherwise recommended. | Para. 113 iii; example after para. 116 |
| Real photo of an empty room, furnished with AI | Label | EU icons page (example for “AI MODIFIED”); examples to para. 92 |
| Scratches, defects, labels or accessories removed from or added to the product with AI | Label | Examples to para. 92; example after para. 116 |
| Real, unchanged product in front of a purely decorative AI background | Not required under the guidelines as long as the scene does not mislead about the product. | Para. 116; example after para. 116 (car) |
| Cut-out: background removed with AI | Not required under the guidelines | Para. 116; examples to para. 92 |
| Colour, light, sharpness, crop or format corrected with AI | Not required under the guidelines as long as the product looks as it really is. | Para. 116; examples to para. 92 |
| Passers-by, cables or dust removed from the background | Not required under the guidelines | Para. 116; examples to para. 92 |
| Several real product photos rearranged with AI | Not required under the guidelines | Para. 116 |
| Clearly unreal motif (cartoon, fantasy creature), product not shown realistically | Not required under the guidelines | Para. 113 ii; examples after para. 116 |
| AI image taken over from the manufacturer, no AI edit of your own | Recommended You are generally not the deployer. | Paras. 14, 16, 17 |
| AI image generated before 2 August 2026 | Recommended Not needed retroactively under para. 154. | Para. 154 |
| AI product description without health, safety or sustainability claims | Not required under the guidelines | Examples to para. 131 |
The Commission's guidelines are not binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the AI Act (para. 5). Market surveillance authorities do follow them, though. Where the guidelines leave a question open or point to the individual case, labelling is the safer choice.
Enforcement and fines
Each Member State designates market surveillance authorities, which can act on their own initiative or after a complaint (para. 151; Article 85). In Germany, the Federal Network Agency (Bundesnetzagentur) has held that role since 29 July 2026 (§ 2(1) KI-MIG) and also runs the central complaints office (§ 8 KI-MIG). Complaints are free of charge and can only be filed through an online form.
Infringements of Article 50 can be fined up to EUR 15 million or 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g)). For small and medium-sized enterprises, including start-ups, the lower of the two amounts applies (Article 99(6)), and the same goes for small mid-cap companies (Article 99(6a)). As an illustration only: with an annual turnover of EUR 2 million, the cap for an SME is 3 %, or EUR 60,000. The actual amount depends on the circumstances, such as gravity, duration, intent or negligence, cooperation with the authority and the measures already taken (Article 99(7)).
In Germany, competition law may apply as well. There are good arguments that Article 50(4) regulates market conduct under § 3a of the Act against Unfair Competition (UWG), which would allow competitors and associations to send formal warning letters. No court has decided the point. By early October 2026 we had not found a published authority decision, judgment or warning letter on Article 50 in Germany. More under Fines and enforcement.
What a label does not do
A label meets the transparency duty; it does not make the image lawful (recital 137). A deep fake that is unlawful as misleading advertising stays unlawful (para. 129). An AI image that shows your product as better than it is can mislead with or without a label. And changing an image of a real person with AI usually needs that person's consent (paras. 127 and 129).
Putting it into practice
- Review your images. Which images have been created or changed with AI since 2 August 2026? The metadata check reads any provenance data in a file. Missing data proves nothing.
- Decide image by image. The labelling check walks you through the questions from the guidelines. The decision is yours.
- Add the label. On the image, visible without a click, with “AI” and a short text such as “AI-generated”. The label tool produces an example.
- Label everywhere the image appears. Product cards, search, banners, blog posts and channels outside your store. Details in AI images in online stores.
- Keep records. Deployers who have not signed the Code of Practice are expected to show how they comply by other means, for instance with a gap analysis against the Code (para. 148).
Frequently asked questions
When did the AI labelling obligation start?
On 2 August 2026 (Article 113 EU AI Act). Deployers, meaning businesses that create AI images or have them created, get no transition period. Only providers of generative AI systems already on the market before that date have until 2 December 2026 for machine-readable marking (Article 111(4)).
Does the obligation apply retroactively?
Not according to the guidelines. Deep fakes generated or manipulated before 2 August 2026 do not need to be labelled after the fact (para. 154). The Commission still encourages it where this takes no disproportionate effort. An old image that is edited with AI again after the start date is a new output and is covered.
Do I need to label AI-generated text?
Only text published to inform the public on matters of public interest (Article 50(4), second subparagraph). Product descriptions and advertising copy are generally outside the scope under the guidelines, unless they contain claims related to health, consumer safety or sustainability (examples to para. 131). Human review before publication, with someone holding editorial responsibility, removes the duty.
Does the EU AI Act labelling rule apply to private individuals?
Not to purely personal, non-professional use (Article 2(10)). The guidelines give the example of AI images of members of one's own household (examples to para. 19). As soon as an activity regularly brings an economic benefit, it counts as professional and the duty applies.
Is a notice in my terms and conditions enough?
No. Information that only appears in terms of use, menus or a manual is easy to overlook and does not count as clear and distinguishable under the guidelines (para. 142). The label belongs on the image itself. A page explaining your labels can add to it but cannot replace it.
What are the penalties for not labelling AI images?
Market surveillance authorities can impose fines of up to EUR 15 million or 3 % of worldwide annual turnover. For SMEs the lower of the two amounts applies (Article 99(4) and (6)). The actual amount depends on the case (Article 99(7)). In Germany, warning letters under competition law are probably possible, but no court has ruled on this yet.
Do I have to label AI images from my supplier?
If you had no say in the use of AI, you are generally not the deployer under the guidelines (paras. 14 and 16). The guidelines still encourage you to keep existing labels and to inform customers (paras. 16 and 17). Ask your supplier whether AI was used. If you edit the image with AI yourself, you are the deployer for that edit.
Sources
All sources read in full. Paragraph numbers (para.) refer to the European Commission's guidelines on Article 50, C(2026) 5054.
- Regulation (EU) 2024/1689 (AI Act)EUR-Lex · Law · 12 Jul 2024
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)EUR-Lex · Law · 24 Jul 2026
- Commission Guidelines on the transparency obligations under Article 50 AI Act, C(2026) 5054 finalEuropäische Kommission · Commission · 20 Jul 2026
- Code of Practice on Transparency of AI-Generated Content (final version)Europäische Kommission · Code of practice · 10 Jun 2026
- EU icons for labelling AI-generated contentEuropäische Kommission · Commission · 24 Sept 2026
- German AI Market Surveillance and Innovation Act (KI-MIG)Bundesgesetzblatt 2026 I Nr. 223 · Law · 28 Jul 2026
- Bundesnetzagentur, AI complaints officeBundesnetzagentur · Authority · 2 Aug 2026
- German Act against Unfair Competition (UWG)gesetze-im-internet.de · Law · 27 Sept 2026
Not legal advice. This content explains the law based on primary sources; it does not replace an assessment of your individual case.



