Product photographySeptember 4, 202615 min read

The EU AI Act and product photography: what changes in 2026

Since August 2, 2026, the EU AI Act requires a disclosure label on AI-generated and AI-changed images that could pass as real. Here is what counts, what is exempt, and what a product photography team should do about it.

EU AI Act - the EU stars circle with the words AI ACT on a dark blue flag background
EU AI Act - the EU stars circle with the words AI ACT on a dark blue flag background

If your team uses AI anywhere in your product photography workflow - a generated background, a virtual model, an AI retouch - you now have a new legal duty to think about. Since August 2, 2026, the EU AI Act (the Artificial Intelligence Act) requires a disclosure label on AI-generated and AI-changed images that could pass as real. This piece of AI regulation is part of the EU's push for human-centric AI and trustworthy AI that protects people's fundamental rights across all kinds of AI applications, not just product photos. The rule is not aimed at everyday editing, but it is specific about where the line sits, and the fines for getting it wrong are significant.

This guide walks through what counts, what does not, and gives practical examples of what a product photography team can do to stay on the right side of it.

Key takeaways

  • Since August 2, 2026, the EU AI Act (Regulation (EU) 2024/1689) requires a disclosure label on AI-generated or AI-changed images. This comes from Article 50, one of the Act's transparency obligations for deployers of AI systems.
  • Normal editing is exempt. That means color correction, cropping, and background cleanup on a real photographed product.
  • Fully AI-generated product scenes, fake models, and AI-invented backgrounds need a machine-readable label.
  • There is no general grace period. A separate transition period runs until December 2, 2026. It only covers the technical marking that AI providers must build into systems that were already on the market before August 2, 2026. It does not delay the disclosure rule itself. (source)
  • Breaking Article 50 can cost up to €15 million or 3% of global yearly turnover, under Article 99(4) of the Act.
  • The rule applies to any business that shows images to people in the EU, no matter where the business is based.

Article 50 of the EU AI Act (Regulation (EU) 2024/1689) says that any AI-generated or AI-changed image that could look real must carry a machine-readable disclosure. This label must be easy to detect. The rule started on August 2, 2026. It does not apply to normal photo editing. It applies to content that shows something a camera never actually captured.

What is the EU AI Act?

The EU AI Act, formally the Artificial Intelligence Act, is the European Union's law for artificial intelligence technologies. It was adopted by the European Parliament as Regulation (EU) 2024/1689 in 2024, published in the Official Journal, and it entered into force soon after. It is being rolled out in stages through 2028. The EU AI Act sets four risk categories, using a risk-based approach so that legal obligations for AI developers and deployers of AI systems scale with the risk an AI system poses to people's safety and fundamental rights. This EU regulation does not cover AI used purely for national security or scientific research.

Risk levelStart dateWhat it coversRelevant to product photography?
Unacceptable risk (banned)February 2, 2025Prohibited AI practices, such as manipulative AI, social scoring, mass facial-image scraping, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, and AI that exploits a person's age, disability, or socio-economic statusNo
High risk - stand-alone AI systems (Annex III)December 2, 2027High-risk AI systems used in hiring, credit scoring, law enforcement, migration and border control management, critical infrastructure, and AI that could affect elections and democratic processesNo
High risk - AI inside a regulated product (Annex I)August 2, 2028AI built as a safety component into products that already follow EU product-safety rules, such as medical devices and machineryNo
Limited risk (transparency)August 2, 2026AI that creates or changes content, or talks directly to peopleYes - this is Article 50
Minimal riskNo required rulesEverything else, including most AI systems and applications like AI-enabled video gamesMost everyday photo editing

General-purpose AI models and general-purpose AI systems - the large models that power many downstream tools - sit alongside this risk ladder under their own rules, with extra duties for the few that pose systemic risks.

The two high-risk dates changed. They moved from the original December 2027 date after a new rule, Regulation (EU) 2026/1744 (known as the "AI Omnibus" or the "Digital Omnibus on AI"), pushed them back, partly to support innovation while the market adjusts to the new AI rules. Article 50 was not affected by this change. It has applied since August 2, 2026, with no exceptions. (source)

Day-to-day AI governance under this EU AI law sits with national competent authorities in each EU country (also called national authorities), working alongside EU-level bodies such as the AI Office and the European Artificial Intelligence Board. This layered structure is part of the wider body of EU law that shapes how AI is built and used across the EU market.

What does Article 50 actually require?

Article 50 says that when an AI system creates or changes an image, sound, or video so it could look real, the result must carry a mark. This mark must say the content is AI-made or AI-changed, and it must be readable by machines. Certain AI systems - those that generate or manipulate content, or that talk directly to people - carry this transparency duty throughout their life cycle, no matter which risk tier they otherwise sit in. The European Commission's guidance sets out two duties:

  • Providers (the companies that build the AI system) must design it so the content carries a machine-readable mark.
  • Deployers (the brands, retailers, studios, or public authorities that use the tool) must tell people when content is a deepfake, or when it could trick someone into thinking they are seeing a real, unedited image.

The main question the Commission asks is simple: does the image show something that really happened, or does it add something that did not happen? A real product photo, color-corrected and cropped, still shows the real object. It is not affected. But a photorealistic model wearing that product, created from nothing, is affected - even though the model is not a real person.

A simple way to think about it: assisted, changed, or created

Before you check an image against the rules below, ask one question: what did the AI actually do to it?

  • If the AI just helped - with research, formatting, cropping, or cleaning up color - this is usually fine. No label needed.
  • If the AI changed something real - an argument, a voice, a scene, or how a product looks or works - you need to think about disclosure. It depends on the effect and how real the result looks.
  • If the AI created something from nothing - a new image, voice, video, or person - this is the case most likely to need a label.

Is there a grace period?

Not for the disclosure rule itself. There is a separate transition period until December 2, 2026. But it only covers one thing: the technical marking that AI providers must add to systems that were already on the market before August 2, 2026 (see "How is AI-generated content technically labeled?" below). It does not delay the deployer's duty to tell viewers about AI-made or AI-changed content. That duty has applied since August 2, 2026. If you publish or re-publish content after that date, you need to check it again - no matter how old the tool is.

Which product photography practices are exempt?

These do not need a disclosure label under Article 50:

  • Color correction, exposure, and white-balance adjustment
  • Cropping, resizing, and sharpening
  • Lighting adjustments made during the shoot or afterward
  • Background cleanup and shadow work on a real, photographed product
  • Normal studio retouching that does not change what the image shows

If a business photographs the real product and edits the image so it still shows that same product correctly, Article 50 does not apply.

Which product photography practices need disclosure?

You need to disclose when the image adds something that was not really there:

  • Fully AI-generated product images, with no real photo behind them
  • AI-generated scenes, virtual backgrounds, or virtual rooms placed behind a real product
  • AI-generated lifestyle images built around a fake ("virtual") model
  • AI-generated colors or materials the product was never actually made or photographed in
  • A realistic fake presenter, spokesperson, or "influencer" shown holding, wearing, or testing a real product. The product may be untouched, but the image still makes people think a real person did a real thing that never happened.
  • Any AI-changed image that could easily be mistaken for a real, unedited photo of a real event

What about AI background removal and AI retouching? Do they need a label?

These sit in a gray area. Each case needs its own judgment:

  • AI background removal: Taking a real, photographed product and placing it cleanly on a white or new background is usually seen as simple editing, not "creating" new content. It becomes a problem when the tool also adds shadows, reflections, or other details that were never captured.
  • AI-powered retouching: Light retouching is fine. But retouching that changes how the product looks in shape, material, or color counts as a real change, and you should disclose it.
  • Real product, new AI-generated background: If the product and its features stay the same, and the new background does not suggest a false fact about the product (like a fake location, event, or use case), you usually do not need to disclose it. But if the background suggests something happened that did not - a real showroom, a real event, a real endorsement - you should add a label.

Common advice in the industry is: when in doubt, add the label. An extra label costs little. A missing label, when one was needed, is what causes real trouble.

What counts as a "deepfake" under Article 50?

For content to count as a deepfake under the Act, it usually needs all three of these things at once, not just one:

  1. AI involvement - the image, sound, or video was made or changed by an AI system.
  2. Resemblance - it resembles real, identifiable natural persons, objects, places, groups, or events.
  3. Looks real - in context, someone could easily mistake it for the real thing.

If even one of these is missing - for example, the content is clearly a fantasy image, or it does not resemble anything real - it is usually not a deepfake under this rule. But it may still need a label under the general rule above, if it could still mislead a viewer.

How is AI-generated content technically labeled?

Two technical standards help put Article 50 labels into practice:

StandardWhat it doesExample values
IPTC metadataAdds a machine-readable field inside the image fileDigitalSourceType: trainedAlgorithmicMedia (fully AI-generated); compositeWithTrainedAlgorithmicMedia (AI mixed with real content)
C2PA Content CredentialsAdds a tamper-proof record that shows how the file was made and editedFull edit history stored in the file

Metadata alone is not enough for people viewing the image. The European Commission has also released a set of optional icons for marking AI content, available since June 2026, as part of its Code of Practice on Transparency of AI-generated Content. Using an icon is not the same as meeting the legal duty. The icon alone does not satisfy Article 50, and the duty does not go away just because a platform removes the icon or the metadata during upload. To follow the Commission's guidance, a label should:

  1. Be visible the first time someone sees the image, not hidden in a terms page
  2. Use plain words, like "AI-modified," together with the icon
  3. Sit on or right next to the image itself

What should a product photography team do to get ready?

  1. Sort your image library into three groups: normal photography and retouching, AI-enhanced real photos, and fully AI-made content.
  2. Ask one question about every image: does it show what was really there, or does it add something fake?
  3. Write down your team's decision rule, even if it's informal. A clear, consistent policy looks much better in an audit than a random decision made on the spot. A short log for each image is usually enough: the tool and version used, what the AI actually changed, the disclosure decision and why, who approved it, and a screenshot of what was published.
  4. Build basic AI literacy into the team. People who choose tools, approve images, or sign off on disclosure decisions should understand, in plain terms, what the AI is doing at each stage of the image's life cycle - not just how to click "approve."
  5. When in doubt, add the label. An extra label costs little compared to the compliance costs of a missing one, which is what gets a business in trouble.
  6. Check marketplace rules too, separately from the law. Marketplaces are adding their own AI-disclosure rules for sellers, and some go further than Article 50.
  7. Hold agencies and freelancers to the same standard. Any outside partner who makes AI-touched images for you should be required, by contract, to tell you which tools and AI methods they used, to have proof of rights and consent for any face, voice, or licensed material, and to name one real person who is responsible for the disclosure decision - not just "whoever uploads it." They should also keep the file's original metadata and labels instead of removing them, and hand over source files and proof of what was published, if asked.

What are the penalties for not following the rules?

Non-compliance is expensive. Under Article 99(4) of Regulation (EU) 2024/1689, breaking Article 50 can lead to a fine of up to €15 million or 3% of the company's total worldwide annual turnover from the year before, whichever is higher. Smaller companies - small and medium-sized enterprises (SMEs) - have a lower limit. Article 99(4) also covers several other rules (Articles 16, 22, 23, 24, 26, 31, 33, and 34) under this same fine level.

This is a lower fine level than the €35 million or 7% limit under Article 99(3), which is only for the banned, prohibited practices under the unacceptable-risk tier. There is a third, even lower level under Article 99(5): up to €7.5 million or 1% of turnover, for giving false or misleading information to regulators. Several bodies can enforce these rules together: national market authorities, the EU's AI Office, and the European Data Protection Supervisor. High-risk AI systems carry their own extra duties, like human oversight and reporting serious incidents, which sit outside this Article 50 penalty structure. Regulators have said they will consider how well a company documented its compliance efforts when deciding on a fine, and legal interpretation of these factors is still developing in practice.

Frequently asked questions

Does the EU AI Act ban AI-generated product photos?

No. Article 50 does not ban AI-generated or AI-edited product images. It just says you must disclose when an image is artificially generated or changed, if it could otherwise look completely real.

Does routine photo retouching need an AI disclosure label?

No. Color correction, cropping, background cleanup, and other normal retouching on a real, photographed product are exempt from Article 50.

When did the AI Act's image labeling rule start?

On August 2, 2026, along with most of the rest of Regulation (EU) 2024/1689. There is no general grace period for this rule. A separate transition period, running until December 2, 2026, only covers a provider's technical marking of AI systems already on the market before that date - not the disclosure duty itself. (source)

Does the AI Act apply to businesses outside the EU?

Yes. Article 50 applies to any business that shows images to people in the EU, no matter where that business is based.

If someone agrees to be shown in an AI image, do I still need to disclose it?

Yes. Getting someone's consent to use their face, voice, or image is a separate matter from disclosure. It's about rights and permission, not about transparency. If the content still meets Article 50's disclosure rules, you must still label it, even with consent.

What is the fine for not disclosing AI-generated images?

Up to €15 million or 3% of global yearly turnover, whichever is higher, with a lower limit for smaller companies, under Article 99(4) of Regulation (EU) 2024/1689.

This article reflects the EU AI Act's transparency rules as they stood in August 2026, including changes made by Regulation (EU) 2026/1744. Guidance in this area is still changing. Talk to a qualified lawyer before you finalize a company-wide labeling policy.

More from this category