EU AI Act: do AI product photos need a label?

a product photo card with a small round label badge pinned in its top right corner and an arc of twelve tiny stars curving behind the card

Under the EU AI Act, product photos generated with AI can need a visible label, and the rule has been live since 2 August 2026. The widely repeated shortcut, that only AI generated humans are covered and object photography is safe, does not survive contact with the Commission’s own guidelines. They say the word “objects” in the deepfake definition includes “consumer goods”, and they give a product advertising example as a deepfake.

That is a change from where this cluster of law looked six months ago, including in our earlier explainer of Article 50, written before the Commission published its guidelines on 20 July 2026. If you read that one, this is the correction.

Not legal advice, and your lawyer beats this blog. Everything is cited to the regulation, the guidelines or the Code of Practice so you can check any of it.

In this post

What changed on 2 August 2026

Article 50 of Regulation (EU) 2024/1689 became applicable on 2 August 2026, on schedule. That is worth stating plainly because a lot of coverage suggested the AI Act had been postponed.

Something was postponed, just not this. The Digital Omnibus, Regulation (EU) 2026/1744 of 8 July 2026, in force 27 July 2026, pushed the high risk system rules out to 2 December 2027 and 2 August 2028. It left the Article 113 application date for Article 50 untouched. The Commission started enforcing on schedule and announced it: “On 2 August 2026, new rules on the transparency of AI systems take effect.”

There is exactly one Article 50 deferral, and it is not yours. A new Article 111(4) gives providers of generative systems already on the market before 2 August 2026 until 2 December 2026 to comply with the machine readable marking duty in Article 50(2). Providers, not deployers. The deployer disclosure duty in Article 50(4) got no grace period at all.

You can now watch that provider duty land in public. Anthropic announced on 14 August 2026 that Claude watermarks the text it generates, citing the AI Act and the transparency Code of Practice it signed in July 2026, and it names a transition period for models launched before 2 August 2026, which is Article 111(4) in practice. What that does and does not do for a store differs sharply between text and images, and we worked it through in do you have to disclose AI product descriptions.

Do AI photos of objects count?

Here is the definition, Article 3(60), in full, because the exact words matter: a deep fake is “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”.

Objects. Not just people. And the Commission’s guidelines spell out what that means: “‘Objects’ is to be understood as realistic, inanimate material items, including buildings, artworks, machinery, consumer goods etc.”

Then the guidelines do something unusually helpful for merchants and give both sides of the line as worked examples.

Commission exampleDeepfake?
“An AI-generated image of a product in advertisement or packaging that can affect the audience’s perception and mislead as to the actual product appearance, characteristics or use (e.g. making the product appear not identical to the real product, more appealing or with improved quality than in real life)”Yes
“A real product (e.g., a car) shown in an advertisement against an AI-generated background and surrounding environment as long as the ad is not likely to mislead the audience about the product’s actual representation and its characteristics and use”No

So the test is not “is there a human in it”. The test is whether the image misleads about the real product. AI colour correction, background extension, background replacement for aesthetic reasons, rearranging real products, rescaling: the guidelines say these are “likely to have only a minor impact” on perceived authenticity. Generating a product that looks better than the one in the box is the problem.

Which, honestly, is a sensible line. It also catches a practice plenty of stores have quietly adopted: generating a hero shot of a product that was never photographed.

Two more exclusions worth knowing. Content that “defies the laws of nature or physics” with no potential to mislead is out. And the artistic or creative carve out does not rescue you, because the guidelines exclude content whose nature “is exclusively informative or commercial and is recognisable as such”. A product page is commercial. That is the whole point of a product page.

Are you a deployer?

Almost certainly yes, if you make the images yourself. Article 3(4) defines a deployer as anyone “using an AI system under its authority” outside personal non professional activity. Typing a prompt into a generation tool for your store makes you a deployer of that system. You are the provider only if you built the model, which you did not.

One genuine escape hatch: the guidelines say a company that “merely commissions an advertising agency to produce an advertisement, without taking decisions and exercising control over whether and how the advertising agency uses AI” is not a deployer. If your agency chooses the tools and you never touch them, the duty sits with them. Put that in the contract rather than assuming it.

Why metadata alone does not do it

This is the paragraph most compliance summaries miss, and it changes what you have to build.

The guidelines say, at paragraph 117, that “deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2) AI Act, since those markings are not immediately clear and distinguishable for the natural persons exposed to the deep fake content.”

Read that twice if you were planning to solve this with Content Credentials. C2PA and IPTC metadata satisfy the provider’s duty. They do not satisfy yours. Article 50(5) wants the information given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”, and the guidelines add that a disclosure fails if it “can be easily overlooked or missed”, is buried in menus, or lives in terms of use nobody reads.

Meanwhile Google pulls the other way, and both duties are real at once. Google’s Merchant Center image specification says: “All images created using generative AI must contain meta data indicating that the image was AI-generated (for example, the IPTC DigitalSourceType TrainedAlgorithmicMedia metadata tag).” Must. And separately: “Don’t remove embedded metadata tags such as the IPTC DigitalSourceType property from images created using generative AI tools.”

So the EU wants a human visible label, Google wants machine readable metadata, and you need both on the same catalog. The useful IPTC values are trainedAlgorithmicMedia for a fully generated image and compositeWithTrainedAlgorithmicMedia for a real photo with AI inpainting or an AI background.

What the label should actually look like

The Code of Practice on Transparency of AI-generated Content, published 10 June 2026, is voluntary, but it is the only document that tells you what a compliant label looks like in practice. The Commission’s opinion of 8 July 2026 concluded it “adequately covers the obligations provided for in Articles 50(2), (4) and (5)”, and roughly 190 organisations had signed by the end of July, 152 of them to the deployer section.

Its deployer measures are refreshingly concrete:

  • The mark itself: “the capitalised acronym ‘AI’ in the English language (e.g., an ‘AI’ icon)”, optionally with a second layer saying modified or generated. There is an official EU icon in the annex, free for anyone to use.
  • Where it goes: “in an appropriate place where no intervening overlay elements exist (e.g., in the top right corner of an image or video deep fake)”.
  • How it behaves: recognisable without requiring user interaction or sustained attention, and embedded directly into the content unless an equivalent interface overlay is used.

Top right corner, two letters, always visible, no hover, no tooltip, no modal. If you were hoping for a discreet footnote under the gallery, that is not what “clear and distinguishable” means here.

Not signing the Code is allowed. The guidelines then expect you to “demonstrate how they have complied through other adequate means” and to run a gap analysis against the Code’s measures. Signing is also a mitigating factor on fines. For a small store, following the Code without signing it is the pragmatic middle.

Penalties, and the number people get wrong

Article 99(4) covers transparency breaches: up to 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher.

The 35 million and 7 percent figure you see quoted everywhere is Article 99(3), and it applies only to the prohibited practices in Article 5. It has nothing to do with labelling. If an article about AI labels quotes 35 million at you, that article did not read the regulation.

For small and medium businesses and start ups, Article 99(6) flips the calculation to whichever of the amount or percentage is lower. Enforcement runs through national market surveillance authorities, and any affected person can complain under Article 85.

If your store is outside the EU

Article 2(1)(c) reaches deployers “located in a third country, where the output produced by the AI system is used in the Union”. The guidelines apply that to posting deepfakes on the open internet where EU dissemination is foreseeable, while excluding content that reaches the EU “through channels that are unforeseeable and outside their control”.

A US store that ships to Germany, runs EU ads, or has a euro currency selector is foreseeably reaching the EU. A hobby store that ships domestic only is a different conversation.

Labelling without breaking your Google feed

This is where merchants get stuck, because Google normally disapproves products whose images carry overlays. Its specification bans “any overlay, for example, watermarks, brand names, logos” on feed images, and the disapproval reason is called Promotional overlay on image.

Google carved out an exception for exactly this case. Its AI content label documentation states: “These labels won’t be in violation of Google policies prohibiting text overlays and watermarks.” It also warns, correctly, that using the feature “doesn’t guarantee your compliance with certain regulations”, so it is not a substitute for your own labelling decision.

The workable setup on Shopify, given the platform has no AI disclosure field of its own:

  1. Tag every product whose images were generated or substantially altered by AI, for example ai-image
  2. Apply a visible AI label to those images, top right corner, in bulk by that tag
  3. Keep the IPTC DigitalSourceType metadata on the file, and do not strip it in your export pipeline
  4. Keep untouched originals so you can restore a product if a classification changes
  5. Write it down: which images, which tool, which date. If a regulator asks, that record is the answer

Step two is the one with no manual path at any real catalog size. We checked every app in both relevant App Store categories, 442 listings, and exactly one ships a ready made AI Generated label: Viking Watermark applies an AI Generated label to selected photos in bulk by collection, tag or product status, marks new uploads automatically, and keeps originals in Shopify Files for one click restore. Free for the first 100 images, $5 a month above that, 5.0 stars from 6 reviews, which is a new listing rather than a long track record.

Ready made AI Generated label and sticker gallery for Shopify product images

Be clear about what an app like that does and does not do. It is the visible label layer. It is not C2PA, it does not write IPTC metadata for you, and it does not make you the provider marking your outputs under Article 50(2). Anyone selling you an app as full AI Act compliance is overselling.

“Fantastic experience. Easy to use. Since the new NY regulation came in, I sent an email to support and within a couple of days, we now have the ability to watermark by photo for each product instead of all the photos. Great technical support in jumping on this right away. Helps us show that not all of our product photos are AI Generated.”

Wildwood Mountain Coffee Co, United States, June 13, 2026, Viking Watermark on the Shopify App Store

Per photo control matters more than it sounds. Most catalogs are mixed: real photography for the products you shot, AI imagery for the ones you did not. Labelling all of them is dishonest in the other direction.

New York, California and the rest

Short version, because the internet has made this more complicated than it is.

  • New York amended General Business Law 396-b, effective 9 June 2026. It covers synthetic performers, defined as digitally created assets giving the impression of a human performance. AI images of objects with no human figure are outside it. Penalties are $1,000 for a first violation and $5,000 for each subsequent one, and it bites only where the advertiser has actual knowledge.
  • California SB 942, as amended by AB 853, became operative on 2 August 2026 and binds “covered providers”, meaning generative AI systems with over a million monthly users. Not you. Large platform duties follow on 1 January 2027.
  • Washington, South Korea and China all place their labelling duties on upstream providers and platforms rather than on a merchant publishing images on its own store.
  • Spain has a bill that would sanction breaches of Article 50, still in the amendment stage as of August 2026. Italy’s enacted AI law contains no content labelling duty at all, despite what a lot of summaries say.

Which means the operative duty for most stores is the EU one, and the New York one if you use AI humans. We go deeper on that in the New York synthetic performer guide and on the practical labelling steps in how to add an AI Generated label to Shopify product images.

And while your catalog is open, two adjacent jobs: making sure the right image shows for the right variant is variant image filtering work, and tidying six near identical colour products into one card is what combined listings handle. Check the state of your feed with our free Google Shopping feed checker before you change any images.

FAQ

Do I have to label AI generated product photos in the EU?

If the image could mislead a shopper about the real product’s appearance, characteristics or use, yes, with a clear and visible disclosure, since 2 August 2026. A real product against an AI background that does not mislead is outside the duty, per the Commission’s own example.

Was the EU AI Act delayed?

The high risk system rules were, to December 2027 and August 2028, by the Digital Omnibus. Article 50 transparency was not. The only related deferral gives providers of pre existing generative systems until 2 December 2026 to add machine readable marking.

Is C2PA or IPTC metadata enough to comply?

Not for a merchant. The Commission’s guidelines state that deployers cannot rely on the provider’s machine readable marking, because it is not clear and distinguishable to the people looking at the image. You need a human visible label. Google separately requires the metadata for feed images.

What should the label say and where should it go?

The Code of Practice describes the capitalised acronym AI, placed where no overlay elements interfere, giving the top right corner of the image as the example, and recognisable without any user interaction. An official EU icon is published free to use.

Will an AI label get my products disapproved in Google Shopping?

Not the AI disclosure label. Google’s documentation says its AI content labels will not violate the policies prohibiting text overlays and watermarks. Ordinary promotional overlays and brand watermarks on feed images still cause disapprovals.

What is the fine for getting this wrong?

Up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher, under Article 99(4). For SMEs and start ups it is whichever is lower. The 35 million and 7 percent figure applies only to prohibited practices under Article 5.

Does Shopify have an AI disclosure setting?

No. There is no product field, metafield or theme setting for it, and Shopify’s acceptable use policy has no AI provisions. Labelling is something you add yourself, through an app or by editing images before upload.

Open your catalog and answer one question honestly: which product images show something that was never photographed? That list is your compliance scope, and it is usually shorter than merchants fear and longer than they admit.

Co-Founder at Craftshift