AI Product Images and the EU AI Act: Who Article 50 Binds

Article 50 of the AI Act started applying on 2 August 2026, and a lot of what is currently ranking for it is being published by companies that sell AI photo tools. The useful way to read the article is not obligation by obligation but person by person: each paragraph is pointed at somebody, and mostly it is not pointed at you.

Two definitions decide where you stand, and both are in Article 3. A provider develops an AI system and places it on the market under its own name — Midjourney, OpenAI, Adobe, the company behind whatever generates your images. A deployer is anyone “using an AI system under its authority”, other than in a purely personal, non-professional capacity. Generating listing photos for a shop is professional use. You are a deployer, and you are never the provider unless you trained and shipped the model yourself.

Hold those two words steady and Article 50 becomes much smaller than it looks.

The four obligations, and who each one is addressed to

Binds providersArticle 50(1)

Tell people when they are talking to an AI

AI systems intended to interact directly with people must be designed so those people know it is an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person.

Reaches you indirectly. If you have put an AI chat assistant on your own storefront, you are choosing the design and configuration, and the practical answer is to label it. This is the genuine seller-facing obligation in Article 50 that almost nobody writes about, because it is not about images.

Binds providersArticle 50(2)

Mark synthetic output in a machine-readable format

This is the paragraph everyone is quoting at sellers, and it is the one that does not apply to them.

Does not reach you. The duty is on the provider of the system that generated the content. Nothing in it obliges the person who later uses an image to add, preserve or verify a mark.

Binds deployersArticle 50(3)

Tell people when emotion recognition or biometric categorisation is being used on them

Aimed at systems that read faces or bodies to infer emotion or category.

Almost certainly irrelevant to a product listing. Worth knowing only if you have added a virtual try-on or face-analysis feature to your own site.

Binds deployersArticle 50(4)

Disclose deep fakes, and AI text on matters of public interest

This is your paragraph. It is the only place in Article 50 where a seller publishing an AI image can be the person in breach.

Reaches you — but only if the image is a deep fake as the Act defines it. That definition is narrow, and it is where the rest of this guide goes.

The marking claim, against the text

The most repeated advice right now is that every AI-assisted product image must carry a visible AI disclosure and embedded provenance metadata. Here is the provision it is supposedly based on.

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated … This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof …”

Regulation (EU) 2024/1689, Article 50(2)

The subject of the sentence is “providers”. The obligation is to mark in a machine-readable format — that is metadata or a watermark, read by software, not a badge a shopper sees. And the standard-editing carve-out is written for the benefit of the tool, describing systems that only assist with editing, not as a permission granted to the person editing.

That last point cuts both ways, and it is the detail most commentary gets wrong in the reassuring direction. The “assistive function for standard editing” exemption sits inside paragraph 2. It does not appear in paragraph 4. So a seller cannot reason “I only used generative fill, which is standard editing, therefore the deepfake paragraph does not apply to me.” Paragraph 4 has its own and much narrower exceptions: law enforcement, and content forming part of an evidently artistic, creative, satirical or fictional work.

The 2 December 2026 date is your supplier's, not yours

A four-month window is being reported as a compliance deadline for anyone using AI images. It is not. The Commission's guidance describes a grace period available “only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation” — that is, extra time for existing generative tools to implement paragraph 2. The Commission also states that content generated before 2 August 2026 does not need to be labelled retroactively.

We could not locate that four-month window in the original text of Regulation (EU) 2024/1689, so it rests on the Commission's own guidance or on a later amendment we have not verified. Either way it is a window granted to model providers. There is nothing in it for a seller to miss.

Where a seller genuinely can be caught

Paragraph 4 obliges deployers to disclose that content is artificially generated or manipulated where it constitutes a deep fake. The Act defines the term:

“‘deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful

Regulation (EU) 2024/1689, Article 3, point (60)

The Commission reads this as three cumulative criteria: resemblance, to something that exists, in a way capable of deceiving as to authenticity. All three have to be present. Apply that to the things sellers actually make and the picture is uneven rather than uniform.

Listing imageReading against the three criteria
Invented AI model wearing your product, plain studio background The model does not exist, so the resemblance-to-an-existing-person limb fails. The product does exist, which is why this is not risk-free, but it is the weakest case for a deepfake finding.
AI image resembling a real, identifiable person wearing your product All three criteria are comfortably met. This is the core case. It also raises image rights and endorsement problems entirely separate from the AI Act.
Your product composited into a recognisable real place — a named landmark, a real shop Places are expressly in the definition. A photorealistic image of a real location that never happened is the situation the paragraph is written for.
Background swap or lighting cleanup on a real photo of the real product Weakest case of all — the scene is not made to resemble a specific existing thing beyond your own product, and nothing false is asserted about authenticity.
Fully synthetic render of a product you actually sell, presented as a photograph Genuinely unresolved. The object exists and the image would read as authentic. We are not aware of this being tested, and we are not going to tell you it is settled.
AI-written product description Outside paragraph 4. Its text limb covers text “published with the purpose of informing the public on matters of public interest”. Product copy is commercial, not that.

Where disclosure is required, machine-readable metadata is not enough on its own. The Commission's position is that deployer disclosure has to be understandable and perceivable by people — a visible or audible label — and that deployers cannot simply rely on the provider's machine-readable marking. Note how that inverts the popular advice: the visible label is not required for ordinary AI imagery, and it is the expected form precisely in the narrow deepfake case where most sellers assume they are safe.

Three more claims worth checking before you act on them

“C2PA is mandatory.” Article 50(2) requires marking to be effective, interoperable, robust and reliable, as reflected in relevant technical standards. It names no technology. C2PA is one way a provider might satisfy a duty that is not yours in the first place.

“You must sign the Code of Practice.” The Code of Practice on Transparency of AI-generated Content was finalised in June 2026 and is voluntary. Signing it is a route to demonstrating compliance, not a requirement; those who do not sign have to demonstrate adequacy another way. The underlying Article 50 obligations bind regardless of whether anyone signs anything.

“Your whole back catalogue needs relabelling.” The Commission states that content generated before 2 August 2026 does not need to be labelled retroactively. If a listing image was made in 2025, this article did not reach back for it.

Not confirmed as of 5 August 2026

The synthetic-photograph question. Whether a photorealistic AI image of a real product you genuinely sell is a “deep fake” turns on reading “objects” in the definition, and we found no authority resolving it. Consumer protection law on misleading commercial practices may well bite before the AI Act does, and it does not care how the image was made.

The legal basis for the December window. As noted above, we could not find the four-month marking transition in the original regulation and have cited the Commission's FAQ for it rather than a provision.

Penalties. Article 99 provides for penalties and leaves much of the detail to member states. Specific figures are circulating; we have not verified them against the article and do not repeat them here.

What marketplaces will require. Amazon and Etsy can impose their own AI disclosure policies whenever they like, and those policies are not constrained by Article 50 being narrower than advertised. Platform rules are the more likely thing to change your listings in the short run, which is the same pattern as the EU packaging EPR marketplace check and GPSR labelling: the regulation sets the floor, the marketplace sets the gate.

What this actually changes for a small shop

For most sellers using AI to produce clean product imagery: nothing, this week. The marking duty is your tool vendor's. Your existing images are not caught. What is worth doing is narrower and cheaper than the advice being sold — label any AI chat assistant on your own site, add a visible disclosure to any image that depicts a real person or a real identifiable place, and keep a note of which images were generated and when. That last habit costs nothing and answers most questions before they are asked.

If you are working on listing imagery itself rather than the law around it, the Amazon main image checker tests the rules that will actually get a photo rejected today, and our guides to pure white background product photos and the shadow mistakes that make a composite look fake cover the craft problems that AI tools tend to introduce and nobody regulates.

Facts verified 2026-08-05 against the sources below. This is a summary for sellers, not legal advice.

Primary sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — full text via EUR-Lex (Article 3, points (3), (4) and (60); Article 50(1)–(7); Article 113, under which the Regulation applies from 2 August 2026 with no carve-out for Chapter IV); European Commission, FAQ on transparency obligations under Article 50 (marking is a provider obligation; the three cumulative deepfake criteria; deployer disclosure must be perceivable by people; the grace period for systems placed on the market before 2 August 2026; no retroactive labelling of earlier content); European Commission, guidelines on transparency of AI-generated content and the Code of Practice on Transparency of AI-generated Content, finalised June 2026 and voluntary. Where a point could not be confirmed on a primary source it is flagged as not confirmed in the text above rather than stated.