Other
20 minute read - Sep 30, 2026

EU's AI Act and What That Means For Your Content Strategy

Under the EU AI Act, AI-generated images fall under Article 50, which has applied since 2 August 2026. AI tool providers must mark outputs in a machine-readable way, and businesses publishing AI images that could pass as real (deepfakes) must label them clearly.

The new label your product page didn't need in July

Picture a spring catalogue refresh. The hero shot of a linen sofa was generated from a prompt, the model wearing your new jacket has never existed, and the "sunlit terrace" behind your hotel's breakfast spread was painted in by an AI tool last Tuesday. All three images went live across your EU storefronts in August.

 

Since 2 August 2026, those images sit inside the transparency rules of the EU Artificial Intelligence Act. Get the disclosure wrong and Article 99 allows fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. And your customers were already asking: almost 90% of consumers globally want to know whether an image was created using AI, according to Getty Images' research across 25 countries.

 

The good news: the rule is narrower than the headlines suggest, and plenty of AI editing needs no label at all. The bad news: the duty is split between your AI vendor and you, your own image pipeline can silently destroy the technical half, and Google and Amazon have layered their own metadata rules on top.

 

This guide covers what Article 50 says, where the timeline landed after the Digital Omnibus, which images need a label, how C2PA and IPTC marking work, and a checklist to run this quarter. It is not legal advice. The Commission's guidance is non-binding and many questions are case-by-case, so take anything material to counsel.

Brown leather lace-up shoes worn on a weathered wooden bench, a real product in real use
Real photography of a real product carries no Article 50 label. The AI variants built from it might.

What Article 50 actually says

Article 50 contains four transparency duties. Two matter for brands publishing imagery, and they land on different parties.

Providers mark

Article 50(2) targets the companies that build generative tools: "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated." The same paragraph exempts systems that "perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof."

Deployers label

Article 50(4) is the one that lands on your desk: "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated." Article 50(5) adds that the disclosure must be "clear and distinguishable" and made "at the latest at the time of the first interaction or exposure."

 

The two duties don't substitute for each other. The Commission's Q&A says deployers "cannot simply rely on the machine-readable marking" embedded by the provider to meet their disclosure obligation. A human must be able to see it.

Are you a deployer?

If your company uses an AI system under its authority for professional purposes, yes. The Commission's Article 50 Guidelines add three details that matter for brands:

 

• Your employees and the freelancers you direct are not separate deployers. The company is. A legal person "remains a deployer even if it involves third parties (e.g. contractors, freelancers)" under its control.

• A company that "merely commissions an advertising agency to produce an advertisement, without taking decisions and exercising control over whether and how the advertising agency uses AI" is not a deployer. The agency is. Most enterprise brands brief and approve heavily, so don't assume this gets you off the hook.

• Being outside the EU doesn't help if you direct content at EU audiences. The Act covers third-country deployers "where the output produced by the AI system is used in the Union", and the Guidelines give the example of a non-EU company running an AI celebrity deepfake in an ad displayed in the Union.

Where the timeline stands after the Digital Omnibus

Many brands heard in late 2025 that the AI Act was being delayed and assumed that included labelling. It didn't.

 

The Commission proposed the Digital Omnibus on AI on 19 November 2025. It became Regulation (EU) 2026/1744 of 8 July 2026, was published in the Official Journal on 24 July, and entered into force on 27 July 2026. Here's what it changed and what it left alone:

 

• High-risk AI systems (Annex III): Moved to 2 December 2027

• High-risk AI in products (Annex I): Moved to 2 August 2028

• Article 50 transparency duties, including deepfake labelling: Unchanged: apply from 2 August 2026

• Machine-readable marking for generative tools already on the market before 2 August 2026: New grace period: must comply with Article 50(2) by 2 December 2026

• Code of Practice status (Article 50(7)): Rewritten so the Commission assesses codes for adequacy and may adopt an implementing act if it deems a code inadequate

 

Two points worth underlining. First, the grace period is for providers and covers marking only; the Commission's Q&A confirms it applies "only as regards the marking and detection obligation". Your labelling duty as a deployer started on 2 August. Second, the same Q&A says content generated before 2 August 2026 does not need to be labelled retroactively, though the Commission encourages it.

The Code of Practice and the Guidelines

The final Code of Practice on marking and labelling of AI-generated content was published in June 2026. The Commission concluded on 8 July that it adequately covers Articles 50(2), (4) and (5), and the AI Board adopted its own adequacy assessment the following day. By the end of July, about 190 organisations had signed, with Getty Images, Lufthansa and Bulgari among the deployer-side signatories.

 

Signing is voluntary. Non-signatories must show compliance "through alternative adequate means" and, per the Commission's Q&A, may face more requests for information. The Commission's interpretive Guidelines on Article 50 followed on 20 July 2026.

 

What's still uncertain: enforcement sits mainly with national market surveillance authorities, and each Member State sets its own penalty rules under Article 99(1). As of late September 2026 there's no body of enforcement decisions showing how strictly "clear and distinguishable" will be read on a product carousel or a four-second story frame. Plan for a conservative reading.

Fully synthetic, AI-edited or composite: which images need a label

This is where most teams over- or under-comply. There are two separate tests, and an image can pass one and fail the other.

Test 1: does the tool have to mark it?

The marking duty doesn't apply to standard editing. The Guidelines list examples that fall under the exception, including "minor cropping, minor colour adjustments or corrections, lightening or darkening, sharpening," removal of dust spots and red-eye, and "deleting and obscuring backgrounds that are visible in the original file." They also list changes that do require marking: "removal, replacement or insertion of objects or persons in existing images" that changes meaning, "altering the body shape or the skin colour of a person," and "creation of composite images" that modify the representation of persons or objects.

Test 2: is it a deepfake you must label?

The Act defines a deep fake as AI-generated or manipulated content that "resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful". The Commission's Q&A breaks this into three cumulative criteria: resemblance, something that exists or could plausibly exist, and a false appearance of authenticity. Context and audience expectations count.

 

The Guidelines get unusually concrete about advertising. Their list of deepfakes includes "an AI-generated image of a product in advertisement or packaging" that could mislead as to its actual appearance, "making the product appear not identical to the real product, more appealing or with improved quality than in real life." Their list of non-deepfakes includes a real car shown in an ad "against an AI-generated background" as long as the ad doesn't mislead about the product, and a campaign of mice arguing over cheese.

 

Here's how that plays out across our verticals. Treat it as a starting framework, not a legal determination:

 

• Real product photo, colour-corrected and cropped. Marked by the tool? No (standard editing). Deepfake label likely? No.

• Real product placed on an AI background for aesthetic reasons. Marked by the tool? Likely, if it's a composite. Deepfake label likely? Unlikely, if the product itself is shown accurately.

• Fully AI-generated packshot of a real SKU that looks better than the real thing. Marked by the tool? Yes. Deepfake label likely? Yes.

• Photorealistic AI model wearing your garment. Marked by the tool? Yes. Deepfake label likely? Yes.

• Empty apartment furnished with AI (virtual staging). Marked by the tool? Yes. Deepfake label likely? Yes: the Commission's icons page uses it as its example of partially AI-modified content.

• AI-generated dish photo standing in for a real menu item. Marked by the tool? Yes. Deepfake label likely? Likely, if it looks like the actual dish and flatters it.

• Hotel room photo with a passerby removed and the light balanced. Marked by the tool? Arguably not. Deepfake label likely? Unlikely: the Guidelines treat removing passersby and lighting tweaks as minor edits.

• Obviously fantastical brand illustration. Marked by the tool? Yes. Deepfake label likely? No, if nobody could take it for real.

 

If your team already sells virtual staging, our guide to the dos and don'ts of virtual staging and the numbers in what virtual staging costs are worth a reread with a label in mind. Food delivery teams filling menu image gaps with generated dishes face the same question.

Don't lean on the artistic exemption

Article 50(4) softens the duty for "evidently artistic, creative, satirical, fictional or analogous" work, but it doesn't remove it. The Guidelines exclude content whose nature is "exclusively informative or commercial and is recognisable as such," and give a synthetic influencer "testing out a sponsored real product" as an example that does not qualify. Some ads may count as creative in specific situations, but a product detail page almost certainly won't.

Empty apartment with bare wood floors and full-height windows, before any AI staging
Furnish this room with AI and the Commission's own icon guidance calls it partially AI-modified.

How machine-readable marking works: C2PA, IPTC and watermarks

Article 50(2) doesn't name a technology. The Code of Practice fills the gap for signatories with a two-layer approach. Providers commit to "digitally signed metadata" recording whether content is AI-generated or manipulated, time-stamped "in a secure and tamper-evident manner," plus an "imperceptible watermark" embedded in the content itself.

 

In practice, three standards do most of the work:

 

• C2PA. The Coalition for Content Provenance and Authenticity publishes an open technical standard for establishing the origin and edits of digital content, known as Content Credentials. It's the signed, tamper-evident layer.

• IPTC DigitalSourceType. A simpler metadata field with a controlled vocabulary. The values that matter are "trainedAlgorithmicMedia" (created using generative AI), "compositeWithTrainedAlgorithmicMedia" (edited using generative AI, such as inpainting or outpainting), "compositeSynthetic" (a composite including generative AI elements) and "digitalCapture" for a real camera capture.

• Invisible watermarks. Pixel-level marks designed to survive when metadata is lost, which is exactly why the Code asks for both layers.

 

The Code also asks provider signatories to prohibit, in their terms, "the intentional removal of or tampering with metadata markings" by deployers or other third parties. Read your AI vendor's terms: stripping those marks may breach them.

The publish-time trap: your pipeline strips the evidence

Here's a failure most compliance guides skip. Your AI tool writes a provenance record into the master file. Then your stack resizes it.

 

Cloudflare's image transformation docs are a clear example. The default metadata setting, "copyright," discards all metadata except the EXIF copyright tag, and for WebP or PNG output "all metadata will always be discarded." C2PA survives only if you turn on the Preserve Content Credentials setting; when it's disabled, "any existing Content Credentials will always be discarded." WordPress behaves the same way by default: its image_strip_meta filter defaults to stripping metadata on resize, and the GD editor "always strips profiles by default."

 

So the IPTC tag and Content Credentials on the full-size master are often gone from the resized WebP your shoppers actually see. That doesn't break your Article 50(4) duty directly, since the visible label is what satisfies it. But it can breach platform rules that depend on the metadata, and it destroys the evidence trail you'd want if a regulator asked how you manage AI content.

 

Fixes worth scheduling:

 

1. Pull a sample of live derivative URLs and inspect them with a metadata reader such as ExifTool. Test every output format.

2. Enable provenance preservation in your CDN or image service where it exists, and check format-specific behaviour.

3. Keep feed images for shopping channels in a format and pipeline that retains metadata.

4. Burn the visible label into the delivered derivative, or render it in the page next to the image, so the disclosure doesn't depend on metadata at all.

How Article 50 stacks with Google and Amazon rules

Marketplace rules aren't the AI Act, and they often bite faster.

 

Google Merchant Center lists "Maintain all AI-generated image metadata" among its minimum image requirements, which means non-compliant products can be disapproved. Google says "all images created using generative AI must contain meta data indicating that the image was AI-generated," names the IPTC TrainedAlgorithmicMedia tag as an example, lists CompositeSynthetic for composites, and tells merchants not to remove it. Add the CDN defaults above and a compliant master file can become a disapproved listing.

 

Amazon's US product image guide asks sellers whose images include photorealistic AI-generated people to add the keyword "contains-synthetic-performer" to the dc:subject (XMP) field, after which Amazon adds a disclosure where applicable. It explicitly excludes real people altered with AI tools and images with no people. The page says it applies to selling in the United States, so check each EU marketplace's own policy before assuming the same mechanism.

 

One helpful nuance from the Guidelines: where a very large online platform or search engine offers a labelling tool that meets Article 50(4), deployers can rely on it within that platform. Outside the platform, on your own site and apps, the label is yours to build.

Where real photography fits

None of this makes AI imagery a bad bet. It makes AI versus camera a decision about each image, not a blanket policy.

 

For the images that carry the most commercial weight (the hero packshot, the menu thumbnail a hungry customer taps, the listing photo a renter uses to decide whether to visit), the cleanest option is a real photograph of the real thing. It isn't a deepfake, needs no label and raises no question about whether the product looks better than it will on arrival. It also pays: at Bring a Trailer, Snappr photos lifted average sale price by 2.5%.

 

AI earns its place on the long tail: seasonal backgrounds, channel crops, colourway variants. The strongest workflow we see is to shoot once and generate the rest from delivered frames, the approach in our guide to AI product photography. Our breakdown of what AI photo editing can and can't do maps neatly onto the standard-editing line, and our furniture and decor and skincare and cosmetics guides show where generated variants help. If you're pricing the reshoot side, our product photography pricing guide breaks down the options.

 

That's the model Snappr is built around: Capture puts a vetted photographer on site for the images that must be real, and Magic handles AI generation and editing for the variants. Enterprise teams get centralised editing and QA on every Capture booking, plus Workflows and API delivery into their own systems. Snappr has captured 250M+ photos and is trusted by over 70% of Fortune 500 companies. Whichever tool produced an AI asset, confirm what marking the file carries and run the two tests above before it goes into an EU channel.

A real photo of the real dish: no disclosure, no metadata to protect, no gap to the plate.

Your Article 50 compliance checklist

1. Inventory every AI tool your teams and agencies use to create or edit imagery, and ask each vendor what machine-readable marking it applies and whether it has signed the Code of Practice.

2. Classify your image library into real capture, standard-edited, AI-edited and fully generated, and record the classification in your DAM.

3. Run each AI-edited or generated asset through the two tests: does it go beyond standard editing, and could it pass as real?

4. Design one visible label, using the optional EU icons or an equivalent, and place it on or directly beside the image so it's visible at first exposure. The Commission's user testing found icons performed better when paired with a short text label such as "modified."

5. Make sure the label survives resharing and downloads. The icons page says it "must be visible when content is reshared or downloaded."

6. Audit your image pipeline for metadata stripping, and fix it for every output format.

7. Tag shopping-feed images with IPTC DigitalSourceType for Google, and apply the Amazon synthetic-performer keyword where relevant.

8. Update agency and freelancer contracts so suppliers declare which assets are AI-generated or AI-edited and who applies the label.

9. Document your decisions on borderline images. Signatories and non-signatories alike may be asked how they comply.

10. Review quarterly. The Code is expected to be updated at least every two years, and national enforcement practice will fill in the gaps.

Build an image program that doesn't need an asterisk

Article 50 rewards teams who know exactly where every image came from. If you're running visual content across EU markets and want a partner that shoots the images that must be real and generates the ones that can be synthetic, talk to Snappr's Enterprise team about building a program that holds up under the new rules.

Frequently asked questions

Does the EU AI Act require labels on all AI-generated images?

No. Deployers must label AI-generated or manipulated images that qualify as deepfakes, meaning they resemble existing people, objects, places or events and would falsely appear authentic. Standard edits like cropping and colour correction don't trigger it, and obviously fantastical images usually don't either.

When did the EU AI Act rules on AI-generated images start to apply?

Article 50 has applied since 2 August 2026. The Digital Omnibus did not delay it, but it gave providers of generative AI tools already on the market before that date until 2 December 2026 to meet the machine-readable marking requirement.

Who is responsible for labelling AI product photos, the AI tool or the brand?

Both have duties. The tool provider must mark outputs in a machine-readable format, and the business publishing a deepfake must add a visible disclosure. Commission guidance says a company that commissions an agency without controlling its AI use is not the deployer, but brands that direct the work usually are.

Do AI-edited product photos need a label under Article 50?

It depends on the edit. Minor retouching, colour correction and removing distractions generally don't need one. Making a product look different or better than it really is, adding AI models, or staging an empty room with AI furniture generally does.

What is the penalty for not labelling AI-generated images in the EU?

Breaches of Article 50 can bring fines of up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Member States set the detailed penalty rules and must take SMEs and small mid-caps into account.

Does C2PA or IPTC metadata satisfy the EU AI Act?

Not for the labelling duty. Machine-readable marks help providers meet Article 50(2), but the Commission says deployers cannot rely on them to disclose deepfakes, which need a label people can see. Google Merchant Center separately requires IPTC metadata on AI-generated product images.

Sources

1. EU AI Act, Article 50 (AI Act Explorer): provider marking and deployer labelling duties, application date

2. EU AI Act, Article 99: penalties for Article 50 breaches, Member State penalty rules

3. EU AI Act, Article 2: territorial scope for third-country providers and deployers

4. EU AI Act, Article 3: definition of deep fake

5. Regulation (EU) 2026/1744, Digital Omnibus on AI (EUR-Lex): Article 111(4) marking grace period, Article 50(7) amendment

6. European Commission: AI Omnibus enters into force: proposal date, entry into force, high-risk timelines

7. European Commission: Q&A on transparency obligations under Article 50: deepfake criteria, grace period scope, no retroactive labelling, marking vs labelling

8. European Commission: Guidelines on Article 50 (PDF): deployer scope, standard editing examples, product advertising deepfake examples, platform labelling tools

9. European Commission: Guidelines on transparency obligations (library page): publication date of the Guidelines

10. European Commission: Code of Practice published: final Code of Practice announcement

11. European Commission: Code of Practice on Transparency of AI-generated Content (PDF): signed metadata, imperceptible watermark, non-removal of markings

12. European Commission: Quick Facts on transparency rules: Code publication month, grace period summary

13. European Commission: opinion on the Code's adequacy: Commission and AI Board adequacy assessments, update cadence

14. European Commission: strong backing for the Code: about 190 signatories and named examples

15. European Commission: EU icons for labelling AI-generated content: icon types, virtual staging example, placement rules, user testing

16. C2PA: Content Credentials open standard

17. IPTC Digital Source Type vocabulary: trainedAlgorithmicMedia, compositeWithTrainedAlgorithmicMedia, compositeSynthetic, digitalCapture

18. Google Merchant Center Help: image link: AI-generated image metadata requirement

19. Amazon Seller Central: product image guide: contains-synthetic-performer XMP keyword

20. Cloudflare Images docs: features (metadata parameter): default metadata stripping

21. Cloudflare Images docs: Preserve Content Credentials: C2PA discarded unless enabled

22. WordPress developer reference: image_strip_meta: metadata stripped on resize by default

23. Getty Images: Building Trust in the Age of AI: consumer demand for AI image transparency

Let Snappr support your business photography needs

The form is only intended for customers. If you're an amazing photographer looking to apply to join the Snappr platform, head on over to instead.
Apply now
Snappr for Business is suited for companies needing 30 or more photoshoots per month. If you have less frequent shoot needs, self-service Snappr is the best solution for you.
Book now by self-service
Snappr for Business is suited for companies needing 30 or more photoshoots per month. If you are not at that level yet, book with regular Snappr.
Thank you! Someone from the Snappr For Business team will be in touch very soon.
Oops! Something went wrong while submitting the form.

Read more Snappr articles

Back to top