EU AI Act Article 50 for E-commerce Product Images

Product photograph with a coral disclosure tab and a separate cyan machine-readable provenance strip

Article 50 of the EU AI Act starts applying on 2 August 2026. For e-commerce teams, the central question is not whether AI touched an image. The question is which obligation applies to the system provider, which applies to the business publishing the asset, and whether the final image could falsely appear authentic or truthful.

This distinction changes the workflow. Machine-readable marking and visible disclosure are related controls, but they are not interchangeable and they do not apply to every edit in the same way. This guide summarizes the operational implications for product imagery. It is not legal advice.

Article 50 separates providers from deployers

A provider develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name. A deployer uses an AI system under its authority for a professional purpose. In a typical agency or retail workflow, the image-tool company may be the provider while the brand or agency publishing the output is the deployer.

The distinction matters because Article 50 assigns different tasks to each role:

  • Providers: systems generating synthetic audio, image, video, or text must support machine-readable marking and detection of generated or manipulated output under Article 50(2), subject to defined exceptions.
  • Deployers: businesses using AI systems must clearly disclose image, audio, or video that constitutes a deepfake under Article 50(4).

The European Commission's current Article 50 FAQ makes clear that embedded machine-readable information does not replace a visible or audible disclosure when the deployer publishes a covered deepfake.

Not every AI-edited product image is a deepfake

The AI Act defines a deepfake as AI-generated or manipulated image, audio, or video resembling existing people, objects, places, entities, or events that would falsely appear authentic or truthful. The Commission describes three cumulative considerations: resemblance, an existing or plausibly existing subject, and a false appearance of authenticity or truthfulness.

Context matters. A shopper viewing an obviously stylized campaign illustration may not expect it to document a real event. A photorealistic image implying that a real product was photographed in a particular location, used by a real person, or endorsed in a real situation carries a different risk.

For e-commerce, useful questions include:

  • Does the generated image preserve the real product's shape, color, components, and included accessories?
  • Does it depict a real person, place, store, certification, event, or product capability?
  • Would an ordinary shopper interpret the scene as photographic evidence?
  • Does the background imply a use, scale, safety characteristic, or environmental claim that was not verified?

A synthetic beach behind a real bottle is not automatically subject to one universal label rule. Its treatment depends on the full deepfake test, deployment context, audience expectations, and other consumer-protection rules. The broader comparison in Deepfake Disclosure Rules: EU AI Act and US States explains why disclosure is only one part of the legal review.

The standard-editing exception is narrower than a free pass

The provider-side marking obligation does not apply when an AI system performs an assistive function for standard editing. The Commission guidance includes practical boundaries and also discusses outputs that do not substantially alter the input or its meaning.

Routine operations may include technical corrections such as resizing, format conversion, exposure adjustment, or limited cleanup. But teams should avoid treating tool names as legal classifications. An “enhancer” can be used gently or aggressively. Upscaling can preserve an image or introduce generated detail. Background removal can isolate a product, while background generation can create a scene carrying new factual implications.

Record what the operation did to the image, not only which product button was clicked.

Machine-readable marking and visible disclosure

Machine-readable marking is intended to help tools and platforms detect that content was generated or manipulated by an AI system. It may use metadata, provenance credentials, watermarks, fingerprinting, or other appropriate techniques. The exact implementation must account for technical limitations and the state of the art.

Visible disclosure serves a different audience. When a published image constitutes a deepfake, the deployer must inform people clearly and distinguishably by first exposure at the latest. A disclosure hidden in metadata, terms and conditions, or a separate help page is not visible to the shopper encountering the image.

Brands should test both layers across the real delivery chain. Content management systems, image optimizers, marketplace imports, social platforms, and screenshots may remove metadata. The guide to C2PA and Content Credentials covers what signed provenance can communicate and where it can be lost.

Application date, grace period, and existing assets

Article 50 applies from 2 August 2026. The Commission states that content generated before that date does not need to be labeled retroactively, although voluntary disclosure is encouraged where practical.

The Commission also describes a limited transition until 2 December 2026 for Article 50(2) marking and detection obligations for certain systems placed on the market before 2 August 2026. That transition concerns the provider-side marking obligation. It should not be treated as a general delay for every deployer disclosure duty.

Because this article is published close to the application date, teams should use the final Commission guidance and current code of practice rather than older summaries or draft timelines.

Penalties are not 7% for Article 50

Older commentary often repeats the AI Act's highest penalty tier without distinguishing the violation. The Commission's Article 50 FAQ states that fines for these transparency obligations can reach €15 million or 3% of total worldwide turnover for the preceding financial year. Proportionality considerations apply, including for smaller businesses.

The headline maximum should not be used as a substitute for legal analysis. Enforcement will mainly sit with national market-surveillance authorities, and the facts, role, scale, and type of violation will matter.

An e-commerce image compliance workflow

  1. Preserve the source. Keep the original photograph and source rights before any automated change.
  2. Record every material operation. Separate technical correction, enhancement, compositing, background generation, and full synthesis.
  3. Identify provider and deployer roles. A brand can be a deployer even when an agency or contractor operates the tool on its behalf.
  4. Apply the deepfake test. Evaluate resemblance, existing or plausible subject matter, authenticity, context, and audience expectations.
  5. Check machine-readable provenance. Confirm what the provider emits and whether downstream systems preserve it.
  6. Design visible disclosure where required. Make it clear, accessible, understandable, and present by first exposure.
  7. Review adjacent obligations. Check advertising claims, consumer protection, likeness rights, copyright, product safety, and platform policies.
  8. Store the decision. Keep the workflow version, reviewer, classification, disclosure copy, publication channels, and accepted asset together.

Using Deep-Image.ai in a documented pipeline

Deep-Image.ai tools can support both technical edits and generated creative work. AI Enhancer Studio can improve an existing product image, while AI Background Generator can create a new setting around the subject.

The compliance classification depends on the operation and final presentation, not the marketing category of the tool. Test representative outputs, protect factual product details, retain originals, and document when a generated scene is intended to look like a real photograph.

The bottom line

Article 50 does not create a simple “AI touched it, label it” rule for every e-commerce image. Providers have machine-readable marking duties for covered generative systems. Deployers have clear disclosure duties when professional use produces content meeting the deepfake definition.

For brands, the practical answer is an asset-level record connecting the original image, transformations, provenance, legal classification, disclosure, and publication context. That process is more reliable than guessing from the final pixels after the campaign is live.