Under Article 50(2) of the EU AI Act, providers of generative AI must mark their output in a machine-readable format, for example with IPTC metadata or C2PA. Retailers acting as deployers must label deep fakes visibly (Article 50(4)) and cannot rely on that metadata to do so (guidelines para. 117).
Keep the metadata anyway; Google Merchant Center requires the IPTC entry for AI images. Missing metadata is no evidence that AI was not involved.
Two duties, two addressees
Article 50(2) addresses providers of AI systems that generate synthetic images, video, audio or text. They must ensure that outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated”. As far as technically feasible, their solutions should be effective, interoperable, robust and reliable. Recital 133 lists watermarks, metadata, cryptographic proof of origin, logging and fingerprints as possible techniques. Systems that only assist with standard editing, or do not substantially alter their input, are exempt.
Article 50(4) addresses deployers, which includes retailers using AI images. In addition to the marking under Article 50(2), they must disclose that a deep fake has been artificially generated or manipulated (guidelines para. 111). This disclosure must be perceivable without technical tools, so deployers expressly cannot rely on the provider's machine-readable marking (para. 117).
Whether an image needs a visible label depends on the deep fake definition (see deep fakes in online stores).
IPTC Digital Source Type
The most widespread machine-readable signal is a single field in the image file's XMP block: Iptc4xmpExt:DigitalSourceType in the namespace http://iptc.org/std/Iptc4xmpExt/2008-02-29/. It may appear once and holds an address from the IPTC controlled vocabulary, for example http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia. Google Search and Google Merchant Center read this field.
The values that matter most for store images, with the IPTC definitions summarised:
| Value | Meaning | Typical store case |
|---|---|---|
trainedAlgorithmicMedia | created by a generative AI model trained on captured content | fully generated product or lifestyle image |
compositeWithTrainedAlgorithmicMedia | augmented, corrected or enhanced with a generative AI model, for example by inpainting or outpainting | real photo with an AI background or AI-extended edges |
compositeSynthetic | a mix of several elements, at least one of them generative AI | collage of a product photo and AI elements |
algorithmicMedia | created purely by an algorithm, without training data | procedurally generated patterns |
algorithmicallyEnhanced | algorithmically corrected while the main content stays unchanged | sharpening, noise reduction |
computationalCapture | several captures merged automatically without generative AI, such as HDR | smartphone photo with multi-frame processing |
digitalCapture | captured from real life with a digital camera | classic product photo |
humanEdits | edited by people with non-generative tools | retouching without AI fill |
Retired values are minorHumanEdits (replaced by humanEdits), digitalArt (replaced by digitalCreation) and softwareImage. Google Merchant Center requires TrainedAlgorithmicMedia for AI images and also wants CompositeSynthetic and AlgorithmicMedia preserved. Google Search supports compositeWithTrainedAlgorithmicMedia; Merchant Center does not mention it. More in Google Merchant Center.
New AI fields in IPTC 2025.1
The IPTC Photo Metadata Standard 2025.1 adds four fields: AI System Used, AI System Version Used, AI Prompt Information and AI Prompt Writer Name. A prompt and the prompt writer's name can contain personal data or business information. For marking, the guidelines say what matters is the artificial origin, not who created the content (para. 94).
C2PA and Content Credentials
C2PA is an open standard by the Coalition for Content Provenance and Authenticity, widely known as Content Credentials.
- Manifest. The file contains a data block about how it was made, for example the action
c2pa.createdwith a digital source type, the generating tool and earlier editing steps. - Signature. The manifest is signed with a certificate and timestamped. The Code of Practice also asks providers for signed, timestamped and tamper-evident metadata.
- Hard binding. Hashes over the file's bytes tie the manifest to the image. If the image changes, the hash no longer matches and the manifest counts as broken.
- Trust List. A list, maintained by C2PA, of trusted certificate issuers. Google only shows AI information from C2PA in “About this image” if the manifest is signed with a certificate from an authority on that list.
Version 2.3 of the specification was released in December 2025. Version 2.4 of April 2026 adds, among other things, a dedicated AI disclosure assertion and allows a digital source type for ingredients that have no manifest of their own. Soft bindings, meaning invisible watermarks or fingerprints, only help to find an image again if its manifest was lost. They do not prove that the image is unchanged.
Invisible watermarks
Some providers also embed an invisible watermark in the pixels, such as Google's SynthID. According to Shopify, Shopify Magic also adds an invisible watermark to generated media, but no visible label. Such watermarks often survive resizing, but only the respective provider's tool can read them. Our tools read metadata, not watermarks.
Why metadata is often missing
- Transition for providers. Systems on the market before 2 August 2026 may deliver without marking until 2 December 2026 (Article 111(4)).
- Background removal and editing. Background removers and many editors write a new file without the old metadata.
- Re-exports and screenshots. Re-exporting, compressing or screenshotting an image usually loses XMP and C2PA entirely.
- Delivery through CDNs. Image servers convert images to other sizes and formats. A Shopify Community thread reported that Shopify's CDN stripped XMP metadata; Shopify staff wrote on 27 July and 4 September 2026 that the issue should be fixed. There is no official changelog entry. In our own test on 3 October 2026, the IPTC entry of one file survived in the original, a resized version and WebP. A C2PA manifest did not remain valid after delivery in a test with four files, because Shopify re-encodes images.
Missing metadata proves nothing
If a tool finds no AI metadata, the image may still have been made with AI. Whether it needs a label is something you or your contractor know, not the file. Conversely, an AI entry is a strong hint, but it does not replace checking whether the image is a deep fake (paras. 111, 117).
Never strip metadata
- The Code of Practice asks AI providers to prohibit, in their terms of use, the intentional removal or tampering of markings by deployers and third parties. Stripping them usually breaches your contract with the AI tool.
- The guidelines expressly encourage preserving markings (paras. 16, 98).
- Google Merchant Center forbids removing embedded AI metadata. Google Search Central notes that removing metadata may be illegal in certain jurisdictions.
- In China and India, removing or falsifying AI labels is expressly prohibited (see worldwide).
That is why we offer no tool for removing metadata.
Writing IPTC breaks C2PA
If the IPTC entry is missing, for example after background removal, you can add it; that helps above all in Merchant Center. If the file carries a C2PA manifest, however, any write changes the bytes, breaks the hard binding and so trades the stronger proof of origin for the weaker one. Do not write to such files, and keep the original whenever you write to a file.
How to check and add metadata
- Open the file in the free metadata checker. It reads IPTC, XMP, EXIF and C2PA information in your browser, with no upload. It does not validate the C2PA signature; that needs the C2PA library and the Trust List.
- Also check the file your store delivers, via the image address from your store or product feed.
- If the entry is missing and the file has no C2PA manifest, add it with the IPTC tool. It writes only the DigitalSourceType field and leaves all other metadata untouched; with C2PA present, it refuses to write.
- Upload the updated file, not a fresh export.
Frequently asked questions
Is machine-readable marking enough for retailers?
No. Deep fakes need a visible label under Article 50(4), because people cannot perceive the marking (guidelines para. 117).
What does trainedAlgorithmicMedia mean?
It is the IPTC value for images created by a generative AI model trained on captured content. Google Merchant Center requires it for such product images.
What is the difference between C2PA and IPTC?
IPTC is a simple text field that anyone can read and write. C2PA is a signed manifest bound to the file through hashes, which shows who issued it and whether the file was changed afterwards.
May I remove AI metadata from images?
We advise against it. Under the Code of Practice, AI providers should prohibit removal in their terms of use, Google forbids it in Merchant Center, and China and India expressly prohibit it.
How do I check whether an image has AI metadata?
Open the original and the version your store delivers in the metadata checker; it shows IPTC, XMP, EXIF and C2PA information without an upload.
Does missing metadata mean an image is real?
No. Metadata is often lost, and AI tools from before 2 August 2026 may deliver without marking until 2 December 2026.
Does writing IPTC break a C2PA signature?
Yes. Any change to the file, including an IPTC entry, breaks the hash binding.
Sources
Para. refers to the paragraph number in the European Commission's guidelines on Article 50, C(2026) 5054.
- Regulation (EU) 2024/1689 (AI Act)EUR-Lex · Law · 12 Jul 2024
- Commission Guidelines on the transparency obligations under Article 50 AI Act, C(2026) 5054 finalEuropäische Kommission · Commission · 20 Jul 2026
- Code of Practice on Transparency of AI-Generated Content (final version)Europäische Kommission · Code of practice · 10 Jun 2026
- IPTC NewsCodes: Digital Source TypeIPTC · Standard · 23 Oct 2024
- IPTC Photo Metadata Standard 2025.1IPTC · Standard · 26 Nov 2025
- C2PA Technical Specification 2.2Coalition for Content Provenance and Authenticity · Standard · 1 May 2025
- C2PA Technical Specification 2.4C2PA · Standard · 1 Apr 2026
- Google Search Central: image metadata (IPTC, C2PA)Google · Platform · 10 Dec 2025
- Google Merchant Center: AI-generated contentGoogle · Platform · 3 Oct 2026
- Google Merchant Center: preserving image metadataGoogle · Platform · 1 Feb 2024
- Shopify Community: CDN stripping IPTC metadataShopify Community · Platform · 4 Sept 2026
- Shopify Magic: media generationShopify · Platform · 3 Oct 2026



