Guide9 min read

Labelling AI-Generated Product Images: What the EU AI Act Means for Online Shops

What Has Applied Since 2 August 2026

The transparency rules of the EU AI Act — Regulation (EU) 2024/1689 — became applicable on 2 August 2026. For an online shop, exactly one article matters: Article 50. It requires certain AI-generated content to be recognisable as such.

For fashion retailers the short version is this: if you publish photorealistic, AI-generated product images, you should expect to have to disclose that. The longer version is more useful, because Article 50 contains two separate obligations, only one of which lands on the shop — and because a meaningful part of how it applies to product photography is simply not settled yet.

Status: August 2026. This is not legal advice. It sets out how we, as the provider of an AI imaging tool, read the situation, and it says plainly where the law is open. The binding text is the Regulation on EUR-Lex; for your own case there is no substitute for your own counsel.

Provider or Deployer? That Distinction Decides Your Obligation

The AI Act assigns duties by role, and the two that matter here are provider and deployer.

  • A provider develops an AI system, or has it developed, and places it on the market under its own name. That covers the model makers — and also tools like GridShot that build a product on top of them.
  • A deployer uses an AI system under its own authority in a professional capacity. That is you, the moment you use an AI imaging tool for your shop.

The term is deliberately broad, and it is not reserved for large companies: a sole trader publishing generated imagery for commercial purposes is a deployer. The only carve-out is purely personal, non-professional use.

From that follows the split worth planning around. Article 50(2) — machine-readable marking — applies to the provider, meaning your image vendor. Article 50(4) — disclosure of deepfakes — applies to the deployer, meaning you. And the second duty cannot be delegated up the chain: the European Commission's FAQ on Article 50 states expressly that "deployers cannot simply rely on the machine-readable marking embedded in the content by the provider" to satisfy their own disclosure obligation.

Is a Product Image Even a "Deepfake"?

The word suggests manipulated political videos, but the Regulation defines it far more broadly. Under Article 3(60), a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

Two elements, both of which must be present. For an on-model product shot:

  • Resemblance. The image shows a person and a real garment that you sell. Note that "objects" is named explicitly in the definition — the product you ship is one.
  • Apparent authenticity. A photorealistic studio image looks like a photograph. That is the entire point of making it.

The practical dividing line is therefore not "was AI involved?" but "does this look like a photograph?". A cut-out packshot where the background was removed or a crease retouched creates no false impression of authenticity — it is a real photograph that was edited. A fully generated studio scene with a model who never stood in front of a camera does.

AI-Generated Models Do Not Get You Out of It

The obvious escape route: if the person depicted does not exist, the image resembles no existing person, so no obligation. That does not hold on the current reading. The Commission FAQ puts it as follows: "Simulated persons, objects, places, entities or events need to resemble someone or something that exists, can plausibly exist or could have plausibly existed in reality." A plausible-looking model is enough.

Synthetic models do carry a real advantage — it just sits in a different area of law. Where no real person is depicted, personality rights and the model-release chain fall away. That is a genuine gain. It does not answer the labelling question.

What Is Unsettled — and Why Not to Argue It Away

Here is where this piece parts company with most coverage: there is no case law on Article 50(4) yet. No court has ruled on whether an AI-generated product photograph is a deepfake requiring disclosure. Germany's Wettbewerbszentrale, whose February 2026 guidance is among the more concrete published readings, says as much about its own analysis: it describes how it currently understands the rules, and expects court decisions over time to show whether the courts agree. It also considers it conceivable that courts will read in a materiality threshold — requiring disclosure only where the deception actually influences the audience's behaviour.

None of that is a reason to relax, and none of it is a reason to panic. It is a cost-benefit calculation, and it resolves cleanly: a label costs you half a sentence under the image. You settle an open legal question in your own favour without waiting years for a judgment. So the defensible line is to label wherever the image reads as a photograph, and to write down why you drew the line where you did.

The opposite error costs too: damaging the product out of caution. A bar stamped across every catalogue image is not required, and it sells worse. The standard asks for clarity, not for prominence.

What the Disclosure Has to Look Like

Article 50(5) sets the frame: the information must be provided "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and must meet applicable accessibility requirements. The Regulation prescribes no specific design, which leaves genuine latitude in wording, symbol, placement and size.

What follows as workable practice:

  • At the image, not in the footer. "At the latest at the time of first exposure" means the notice has to be there when the image comes into view. A line in your terms, your imprint or at the very bottom of the page does not do it — the Commission FAQ is explicit that disclosure confined to terms, documentation or hidden menus is insufficient.
  • In the language of the market you sell to. A disclosure the audience does not parse is not a clear one.
  • A notice per image set, rather than a badge on every file. A caption under the gallery generally carries, as long as it sits where the images are seen. Per-image overlays are the safe option, not the only defensible one.
  • Text, not a bare symbol. The EU now publishes official icons for labelling AI-generated content, free to use without attribution. The Commission notes there that performance improved across all measures when the icon was accompanied by a text label, and that labels should use plain language and avoid jargon.
  • Accessible. A notice that exists only as pixels does not exist for a screen reader. Mark it up as text rather than burning it into the file.

The Second Obligation — Not Yours, but It Shapes Your Vendor Choice

Article 50(2) requires providers of generative systems to ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". That means technical markers inside the file — watermarks, metadata, cryptographic provenance — not visible labels.

The duty sits with your tool vendor. Two things are still worth knowing.

First, the deadline. Per the Commission FAQ, a limited grace period exists "only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation (Article 50(2))"; providers of such systems must comply "only as from 2 December 2026". That grace period covers paragraph 2 alone. Your own disclosure duty under paragraph 4 has applied since 2 August 2026 with no transition.

Second, the question that actually matters in a dispute. A marker inside a file rarely survives your own pipeline: every crop, every WebP conversion, every export from a shop system strips metadata by default. So do not assume anyone will later tell from the file how an image was made. What you need is more mundane and more valuable: a list of which images are AI-generated. A catalogue of 3,000 articles fed by three image sources — legacy photography, supplier assets, generated views — cannot be reconstructed after the fact. Ask that of any image vendor before the volume exists, not after.

Alongside this, a Code of Practice on Transparency of AI-generated Content was published on 10 June 2026 and had roughly 190 signatories by late July 2026. It is voluntary; the underlying Article 50 obligation is not. Section 1 addresses providers, Section 2 deployers.

What Non-Compliance Costs

Article 99(4) sets the ceiling for Article 50 breaches at up to EUR 15 million or 3 % of total worldwide annual turnover, whichever is higher. For SMEs, including start-ups, Article 99(6) reverses that: the lower of the two applies. That exception is routinely left out of the coverage, and it changes the picture substantially for most fashion retailers.

In practice, a regulator's fine is not the likely route in any case. In Germany, the Wettbewerbszentrale takes the view that AI Act breaches can simultaneously constitute unfair competition, which lets competitors and industry associations pursue injunctive relief directly. The realistic enforcement vector is a cease-and-desist letter from a competitor — faster to start, cheaper to bring, and far more probable than a supervisory proceeding.

That cuts both ways, which is the part vendors tend to skip. Advertising "AI Act compliant" or a labelling feature you do not actually ship is a false statement about a material characteristic of your offering. Overclaiming compliance is its own unfair-competition exposure.

An Action List for Shop Operators

  1. Inventory first. Which images are fully generated, which merely edited, which conventionally photographed? This is the actual work, and it gets more expensive as the catalogue grows, not less.
  2. Draw the line. Label photorealistic on-model views. Cut-outs, colour correction and retouching on a real photograph, on the current reading, no. Label borderline cases.
  3. Decide placement. At the product page gallery — not the footer, not the terms.
  4. Fix the wording and use it consistently. "Image generated with AI" is unambiguous and undramatic.
  5. Check accessibility. The notice must exist as text, not as a graphic baked into the image.
  6. Walk the channels separately. Shop, newsletter, social and paid ads are separate publications. Marketplaces add their own field structures and rules — the technical requirements of the major European platforms are collected in our overview of fashion marketplace image requirements.
  7. Ask your vendors one question. Can you tell me, per image, whether and how it was generated? A vendor without an answer has moved the burden of proof onto you.
  8. Document the decision. A paragraph in your wiki explaining where you drew the line and when. On an unsettled question, a reasoned decision is what you have to show.

How We Handle It Ourselves

A guide is worth little if its author ignores it. Every AI-generated example image on our marketing pages and in this blog is labelled as such — a text label at the image or a notice on the image set, in the language of the page. On our own website we are a deployer, and we treat ourselves as one.

As a provider we are additionally subject to Article 50(2). For machine-readable marking, the grace period described above runs to 2 December 2026, and we are working towards it. What we do not do is claim our tool makes you compliant: whether a publication meets the requirements is decided on your side, not ours. Nor do we burn a visible label into your image files by default — placement and wording belong to your brand.

What we provide is the starting point for your obligation: images with a recorded origin and generation timestamp. GridShot turns existing product photography into on-model views; one run returns 16 to 25 variations in 5 to 15 minutes. Billing is USD 1 per published image plus the compute actually used, which lands at a few cents, with no subscription and USD 10 of starting credit. What the equivalent volume costs through conventional production is broken down in Fashion Photoshoot Costs.

Frequently Asked Questions

Do I have to label AI-generated product images in my online shop?

On the current reading, yes, where the images are photorealistic. As a commercial user you are a deployer under the AI Act and subject to Article 50(4), which requires disclosure for deepfakes. Article 3(60) defines a deepfake as AI content resembling existing persons or objects that would falsely appear authentic — a generated studio shot of your real product meets both limbs. There is no case law yet; since a label costs almost nothing, it is the straightforward call. Status: August 2026, not legal advice.

Is a note in the footer or the terms and conditions enough?

No. Article 50(5) requires the information to be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", so it has to be perceivable where the image is seen — at the product page gallery. The European Commission's Article 50 FAQ states expressly that disclosure confined to terms of service, documentation or hidden menus does not satisfy the obligation.

Does the duty apply if the model itself is AI-generated?

On the current reading, yes. The Commission FAQ only requires that simulated persons or objects resemble someone or something that "exists, can plausibly exist or could have plausibly existed in reality". A plausible-looking synthetic model clears that bar. Synthetic models do help elsewhere — no personality rights and no model release, because no real person is depicted — but they do not remove the labelling question.

Do cut-out packshots and retouched photographs need labelling?

On the current reading, no. A real photograph with the background removed, the colour corrected or a crease retouched creates no false impression of authenticity — it is authentic. For the provider obligation in Article 50(2) the Regulation expressly carves out systems performing an assistive function for standard editing that do not substantially alter the input data or its semantics. The further the editing moves toward a newly generated scene, the more the assessment tips. Label borderline cases.

What is the difference between Article 50(2) and Article 50(4)?

Article 50(2) obliges providers of generative AI systems to mark outputs in a machine-readable format — technical markers in the file, such as metadata or watermarks. Article 50(4) obliges deployers to disclose deepfake content to the people who see it — a visible, human-readable notice. The first is your vendor's job and benefits from a grace period to 2 December 2026 for systems already on the market before 2 August 2026. The second is yours and has applied since 2 August 2026 without transition.

What happens if I do not label?

Article 99(4) provides for fines of up to EUR 15 million or 3 % of total worldwide annual turnover for Article 50 breaches, whichever is higher; under Article 99(6), SMEs and start-ups are subject to the lower of the two instead. The more probable route is different: in Germany the Wettbewerbszentrale considers AI Act breaches capable of constituting unfair competition, which allows competitors and associations to seek injunctions. A cease-and-desist letter is the likelier consequence than a regulatory fine.

Ready to try it yourself?

Create your first product photos in under 5 minutes. Free.

Start free