# Do You Have to Label AI Images in the EU? The AI Act's Article 50, in Plain English

> Since 2 August 2026, the EU AI Act requires some AI-generated images to be labelled. Who has to do it, what counts as a deepfake, whether product photos with a removed background are affected, and what a label has to look like.

*Published: 2026-09-21* · *9 min read*

Canonical URL: https://timestampcamera.net/photo-guides/eu-ai-act-label-ai-images


Probably not for every AI image, but quite possibly for some of yours. Since 2 August 2026, the EU's AI Act requires businesses and professionals to clearly disclose **deepfakes**: AI-generated or AI-manipulated images, audio, and video that look like real people, places, or events and could be mistaken for the real thing. Personal, non-professional use isn't covered. Ordinary edits, like cropping, colour correction, or removing a background, generally don't make an image a deepfake. And the companies that make AI tools have a separate duty to mark their output in a machine-readable way.

That's the short version. The details matter, though, because the fines can reach 15 million euros or 3% of worldwide annual turnover, and because a lot of what's been written about this rule is either alarmist or vague.

One note before we start: this is an explainer, not legal advice. We've based it on the text of Article 50 and on the European Commission's guidelines published in July 2026. The Commission itself points out that its guidelines are non-binding, and that only the Court of Justice of the EU can give the final interpretation.

## Two different duties, for two different groups

Article 50 splits the work between two kinds of "operator," and it helps to know which one you are.

**Providers** are the companies that build AI systems and put them on the EU market: the makers of image generators, chatbots, and editing tools. Under Article 50(2), they must make sure that what their systems generate is **marked in a machine-readable format** and detectable as AI-generated or manipulated. Think invisible watermarks or signed metadata. Providers outside the EU are covered too, if their output is used in the EU.

**Deployers** are the people and organisations that use those AI systems in their work. Under Article 50(4), deployers who create deepfakes must **disclose** that the content is artificially generated or manipulated.

Most businesses reading this are deployers, not providers. You use an image generator. You didn't build one.

## Does it apply to you?

The key line is between personal and professional use.

The Commission's FAQ gives a clear example: someone who uses AI in their personal capacity, say to make a deepfake and post it on social media, is doing something personal, and that's outside the scope of the AI Act. It may still be illegal for other reasons, but Article 50 isn't the rule that applies.

It changes when there's regular economic benefit involved. If you're a freelancer, a content creator who earns from your work, or anyone using AI as part of a business, trade, or profession, you count as a deployer.

A few more details from the guidelines that answer common questions:

- **Employees aren't separate deployers.** If a designer at an agency uses AI under the agency's instructions and control, the agency is the deployer, not the individual designer.
- **Commissioning isn't deploying.** A company that simply hires an advertising agency to make an ad, without deciding whether or how the agency uses AI, is not the deployer. The agency is.
- **Where you're based doesn't help.** A company outside the EU that uses AI to make a deepfake for an advert shown in the EU is also a deployer under the Act.

## What actually counts as a deepfake

This is the question that decides almost everything. The AI Act defines a deepfake as AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful.

The Commission breaks that into three conditions, and all three have to be met:

1. **Resemblance.** It closely resembles its subject.
2. **Existing.** The subject is someone or something that exists, or could plausibly exist.
3. **False appearance of authenticity.** It could mislead someone into thinking it's real.

That third condition does a lot of work. Context matters: the audience, where the content appears, and what people expect. The guidelines give examples on both sides, and they're more useful than any definition:

| Likely a deepfake | Likely not a deepfake |
|---|---|
| An AI image of two real footballers in front of what looks like a stadium | An AI image of a sphinx flying over the Eiffel Tower |
| A realistic AI avatar of a company's CEO congratulating staff | AI-generated mice arguing about cheese in a cheese advert |
| An AI video of someone resembling a politician giving a speech | An AI cartoon based on a photo of a historical event |
| An AI product image that makes the product look better than it really is | A real car shown in an advert against an AI-generated background, as long as the ad doesn't mislead about the car |

## "I just removed the background from my product photos." Do I need a label?

If you sell online, this is probably the part you care about, because a lot of sellers now use AI tools to clean up product photos. We make one of those tools, so we read this part of the guidelines closely.

The short answer is: generally no, as long as the product itself isn't misrepresented.

The Commission's guidelines list "deleting and obscuring backgrounds that are visible in the original file" among the examples of **standard editing**, alongside minor cropping, colour correction, and sharpening. They also say that AI-powered colour correction, background extensions, and adjustments or replacements of backgrounds for clearly aesthetic purposes in product advertising are likely to have only a minor impact on how people judge the authenticity of the ad and the product.

The line is crossed when the AI changes the product. The guidelines' own example of a deepfake is an AI-generated product image that could mislead people about how the product actually looks, what it does, or its quality: making it look different from the real thing, more appealing, or better than it is in real life.

So a real photo of a real shoe, with the messy background swapped for plain white, is standard editing. An AI image that smooths out the shoe's stitching, changes its colour, or invents details it doesn't have is a different story, and it could also be a problem under consumer protection law, with or without the AI Act.

## What a label has to look like

If you do publish a deepfake, the rules on disclosure are practical:

- **It has to be clear and distinguishable**, and people have to see it at the latest the first time they're exposed to the content.
- **It has to work without special tools.** The Commission says a disclosure should be perceivable by people, for example with a visible or audible label, without needing any technical tool or extra action. That means **invisible metadata or a watermark isn't enough on its own.** The provider's machine-readable marking is one obligation. Your visible disclosure is another.
- **Art and satire get lighter treatment.** If the deepfake is part of an evidently artistic, creative, satirical, or fictional work, you still have to disclose it, but in an appropriate way that doesn't spoil the display or enjoyment of the work. The guidelines say what counts as appropriate is decided case by case.

For a single image, one simple way to do that is a short visible note on the image or right next to it, like "AI-generated image," placed where people will see it at the same time as the image.

## What about AI-written text?

There's a separate rule for text. AI-generated or manipulated text published to inform the public on matters of public interest, like politics, public health, or the economy, has to be labelled too. But there's an exception: if the text has gone through genuine human review or editorial control, and a person or organisation takes editorial responsibility for it, it doesn't need a label. The Commission is clear that a spell-check doesn't count as human review.

## Key dates

- **2 August 2026:** Article 50 applies. From this date, deployers must disclose deepfakes.
- **2 December 2026:** the deadline for AI systems already on the market before 2 August 2026 to add machine-readable marking. This grace period only covers providers' marking duty, not deployers' disclosure duty.
- **Nothing retroactive:** content created before 2 August 2026 doesn't have to be labelled, though the Commission encourages it where possible.

Enforcement is mainly up to national market surveillance authorities in each member state. The Commission also published a voluntary Code of Practice on marking and labelling AI-generated content, which it says gives signatories more legal certainty.

## How to check whether an image carries an AI mark

If you're on the receiving end, wondering whether an image was made with AI, the machine-readable marks providers now have to add can help, but only when they survive. The most common format is Content Credentials, based on the C2PA standard. We explain how to read them in [how to check Content Credentials](/photo-guides/how-to-check-content-credentials-c2pa).

Two cautions. First, marks are often stripped when images are screenshotted, re-saved, or uploaded to platforms, so a missing mark proves nothing. Second, no automated check is perfect. Our guide on [how to detect AI-generated images](/photo-guides/how-to-detect-ai-generated-images) covers the other clues, and the [photo forensics tool](/photo-forensics) looks for signs of editing in a file, all in your browser.

## The practical takeaway

For most businesses, the checklist is shorter than the headlines suggest:

- Ordinary photo editing, including removing or replacing a background for a cleaner product photo, generally doesn't create a deepfake, as long as the product isn't misrepresented.
- If you use AI to create realistic images of real people, real places, or realistic events, and you use them professionally, label them visibly.
- Don't rely on invisible metadata to do the labelling for you.
- If a case is borderline, the Commission's guidelines have dozens of worked examples, and a lawyer can tell you where your specific use falls.

Sources: Regulation (EU) 2024/1689 (AI Act), Article 50, via the European Commission's AI Act Service Desk; European Commission, "Transparency obligations under Article 50 of the AI Act" (FAQ); European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems, C(2026) 5054 final, 20 July 2026.
