AI Fashion Imagery and the EU AI Act: What You Have to Label
By Ergini, Software & AI Developer
TL;DR
If you sell to EU customers and your product images show an AI-generated person, or a real model altered by AI, you now have disclosure obligations under Article 50 of the EU AI Act. The deepfake rule in Article 50(4) applies regardless of commercial intent, so there is no marketing exemption. The machine-readable marking rule in Article 50(2) falls on whoever generates the imagery, which is your tooling vendor if you buy and you if you build. Both became enforceable on 2 August 2026, with marking grace to 2 December 2026 for systems already on the market. A fully synthetic model on a plain background is a different case from a real model's likeness altered by AI, and the second is where the risk actually sits.
The thing nobody selling you AI imagery is mentioning
AI-generated on-model imagery went from novelty to normal in about eighteen months. It is cheaper than a shoot, faster than a shoot, and lets you show every SKU in every colourway on a model without booking anyone. I have written about how it works and what it saves, and I stand by both.
What changed on 2 August 2026 is that if you sell into the EU, that imagery now carries legal obligations. Article 50 of the EU AI Act became enforceable on that date and, unlike the high-risk rules everyone spent two years preparing for, it was not deferred by the Digital Omnibus. Deepfake disclosure and machine-readable marking are live now.
The reason this has stayed quiet is that the fashion and e-commerce conversation about AI imagery has been almost entirely about cost and quality, and the compliance conversation about the AI Act has been almost entirely about high-risk systems in hiring and lending. The intersection is where a lot of brands currently are, and almost nobody is writing about it.
The usual disclaimer, meant seriously: I am an engineer, not a lawyer. I build the technical controls and I work alongside counsel who make the legal calls. What follows is what to put on the roadmap.
Which rules apply to fashion imagery
Two of Article 50's four obligations touch generated imagery, and they land on different parties.
| Article | What it requires | Who carries it |
|---|---|---|
| 50(2) | Synthetic image output must be marked in a machine-readable format and be detectable as artificially generated | The provider of the generative system: your imagery vendor if you buy, you if you built it |
| 50(4) | Deepfake content must be disclosed as artificially generated or manipulated | The deployer: the brand publishing the imagery, which is you |
Read that table twice if you buy your imagery from a tool. Purchasing the tool moves the marking obligation to the vendor. It does not move the disclosure obligation, because you are the one publishing the image on your product page. Vendors are not, in my experience, volunteering this in sales conversations.
"But it is just advertising"
This is the objection I hear first and it does not survive contact with the text. The deepfake disclosure obligation applies regardless of intent. There is no exemption for benign purposes, no exemption for advertising, and no exemption for the fact that everyone knows fashion photography is retouched.
The definition turns on whether the content appreciably resembles real people, places or events and would falsely appear authentic. On-model product photography is engineered to do exactly that. Its entire commercial value comes from looking like an authentic photograph of a real person wearing the garment, because that is what makes a shopper believe the fit.
There is a narrow accommodation for artistic, creative, satirical, and fictional works, where disclosure is reduced to noting the existence of generated content in an appropriate manner that does not spoil the work. A product listing is not that. An editorial campaign might be closer, and that is a conversation for your counsel rather than an assumption to build on.
Three cases, from clearly covered to genuinely arguable
Not all AI imagery carries the same exposure, and the distinctions are worth drawing carefully because they change what you have to do.
1. A real model, altered by AI. You photographed someone, then changed their pose, swapped a garment onto their body, adjusted their proportions, or placed them somewhere they never stood. This is manipulated content that appreciably resembles a real person and appears authentic. It is the clearest case and the one carrying the most risk. It is also where a second, entirely separate legal question lives: whether your contract with that model actually permits it. Likeness rights and the AI Act are different regimes and brands routinely conflate them.
2. A fully synthetic model who does not exist. This is the genuinely arguable one. A narrow reading says an invented person is not a real person, so the deepfake definition is not engaged. A broader reading notes the image still falsely appears to be an authentic photograph of an actual human. Given how cheap disclosure is and how large the penalty ceiling is, my advice is to disclose and stop thinking about it. This is not the hill.
3. No person at all. Flat lays, ghost mannequin shots, garments on a plain background, generated backdrops with no human subject. The deepfake obligation in 50(4) is not engaged because there is no person being appreciably resembled. The machine-readable marking obligation in 50(2) still applies to the generating system, but that one sits with the provider. If your catalog is entirely product-only imagery, your exposure here is genuinely low.
What to actually implement
The good news is that this is a small amount of engineering. The work splits into three pieces, and only one of them has a deadline attached.
1. Visible disclosure on the product page. A legible line near the imagery stating that it is AI-generated. It must be clear, distinguishable, and accessible, which rules out a footer line, faint grey text, or something that only appears after a click. The test to apply is whether an ordinary shopper looking at the image would notice it. This is already due, with no grace period. It is an afternoon of work on most storefronts.
2. Machine-readable marking on the files. The standard the industry has converged on is C2PA Content Credentials: cryptographically signed provenance embedded in the image file itself. A caption rendered on your page does not satisfy this, because it is not attached to the file and does not survive a download. If you buy your imagery, ask your vendor directly whether their output carries C2PA credentials, and treat a vague answer as a no. If you generate in-house, this is yours to build, and the deadline is 2 December 2026 for systems that were already running before August.
3. A provenance log. A record of what was generated, when, from which source assets, and which model version produced it. This is not explicitly required by name, and it is the item I push hardest anyway, because it is cheap and it answers questions from every direction: a regulator, a marketplace compliance review, a model whose likeness was used, or a customer complaint. It is also the only layer that survives after metadata has been stripped by a social platform or a marketplace re-encode, which they routinely do.
The marketplace problem
Worth flagging because it catches people out. Most marketplaces and social platforms re-encode uploaded images, and re-encoding strips embedded metadata including C2PA credentials. So imagery that was properly marked when it left your pipeline can arrive on a marketplace listing carrying nothing at all.
This is not a reason to skip the marking. It is a reason for the layered approach: the embedded credential covers the file you control, an invisible watermark survives more transformations, and the server-side provenance log covers the case where both are gone. It is also a reason to keep your visible disclosure in the copy fields you control on those listings, since those are not stripped by an image pipeline.
What this costs, honestly
Far less than the compliance framing suggests. Visible disclosure across a storefront is an afternoon. A provenance log is a day or two. C2PA signing in a generation pipeline is a few days if you own the pipeline, and a procurement question rather than an engineering one if you do not.
Compare that to the alternative of discovering the requirement during an enterprise retail partner's compliance review, or during a marketplace audit, with a catalog of thousands of images already published and no record of which are generated. Retrofitting provenance onto a catalog you cannot distinguish is the expensive version of this problem, and it is entirely avoidable by starting the log now even if nothing else ships this quarter.
Frequently asked questions
Do I have to label AI-generated product images in the EU?
If the image shows a person and would plausibly pass as a real photograph, yes, under Article 50(4). There is no exemption for commercial or advertising use.
Does it apply to a fully synthetic model?
Genuinely arguable, since the deepfake definition turns on resemblance to real persons. Given the penalty exposure and the trivial cost of disclosing, disclose anyway.
What about AI-altered photos of a real model?
Clearly covered, and the highest-risk case. Note that likeness rights under your model contract are a separate question from the AI Act.
Is my vendor responsible, or am I?
Both. Machine-readable marking under 50(2) sits with whoever provides the generative system. Deepfake disclosure under 50(4) sits with you as the brand publishing the image. Buying a tool does not remove the second.
When did this take effect?
2 August 2026 for both, undeferred by the Digital Omnibus, with marking grace to 2 December 2026 for systems already on the market before August.
How should the disclosure look?
A legible line near the imagery, not a footer note or faint text. The test is whether an ordinary shopper would notice it while looking at the image.
Bottom line
AI-generated on-model imagery is a deepfake under the EU AI Act, the disclosure obligation applies regardless of commercial intent, and it has been enforceable since 2 August 2026. Buying your imagery from a vendor moves the marking obligation but not the disclosure one. The engineering is small: a visible label, C2PA credentials on the files, and a provenance log you will be glad to have.
The wider picture, including the other two Article 50 obligations and what the Digital Omnibus actually deferred, is in the Article 50 guide. If you want it built rather than explained, that is my EU AI Act compliant development work.