MannequinIA · Guide

EU AI Act Article 50: what changes for AI-generated product photos

On 2 August 2026, Article 50 of the EU's AI Act becomes applicable. Here is what it concretely requires from brands and e-commerce sellers using AI-generated product imagery — no marketing, just the facts.

This page is informational, not legal advice. Verify your own situation with qualified counsel.


In short

From 2 August 2026, Article 50 of Regulation (EU) 2024/1689 (the AI Act) imposes two distinct obligations on AI-generated or manipulated images. First, Article 50(2) requires the provider of the AI system — the maker of the generation model — to mark its outputs in a machine-readable format that is detectable as artificially generated: an invisible pixel watermark, backed by C2PA provenance metadata. Standard editing that does not substantially alter the content is exempt — background removal, upscaling, colour correction — but generating a synthetic model wearing a garment is not. Second, Article 50(4) requires the deployer — the brand publishing the image — to clearly disclose, at the point a person first encounters the content, when it qualifies as a "deepfake". The legal definition of a deepfake covers content resembling existing persons, objects, places, entities or events that would falsely appear authentic — the word "objects" is explicitly part of that definition, which means a generated product photo can plausibly fall within it even when the model is entirely synthetic. A grace period runs until 2 December 2026, but it applies only to the technical marking obligation, and only for systems already on the market before 2 August 2026. Penalties can reach €15 million or 3% of worldwide turnover, though the law requires regulators to take the interests of SMEs into account.

Timeline: what happens, and when

On 20 July 2026, the European Commission published its final Article 50 guidelines, together with a Code of Practice on the Transparency of AI-Generated Content. The Code is voluntary — the Commission has confirmed it as an adequate means of demonstrating compliance, but adopting it is not itself mandatory.

20.07.2026Commission's final guidelines + Code of Practice (voluntary).
02.08.2026Article 50 becomes applicable.
02.12.2026End of the grace period for machine-readable marking (existing systems only).

The two obligations in Article 50 — and why they get confused

Most coverage talks about "the AI transparency obligation" as if it were a single thing. It isn't: Article 50 sets out two separate obligations, owed by two different parties.

Article 50(2)

The provider of the AI system

Mark generated or manipulated images in a machine-readable format, detectable as artificial.

Invisible pixel-level watermark + C2PA provenance metadata.

Article 50(4)

The deployer — the brand publishing the image

Where the content is a deepfake, clearly disclose it at the point a person first encounters the visual.

Clear disclosure at the point of contact — not necessarily technical marking.

What is exempt from the marking obligation — and what isn't

Article 50(2) carves out an exemption for systems performing an assistive function for standard editing, or that do not substantially alter the input data or its semantics.

Exempt

  • Background removal or replacement
  • Upscaling (resolution enhancement)
  • Colour correction

Not exempt

  • Generating a synthetic model wearing the garment
  • Any substantial alteration of the content or its meaning

The deepfake question for a product photo

Article 3(60) defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events, and that would falsely appear to be authentic. The word "objects" is explicitly part of that definition.

A generated photo of a real garment that looks like an actual photograph therefore reasonably falls within that definition — even when the model wearing it is entirely synthetic and resembles no real person. The exception for manifestly artistic, creative or satirical works, which allows for lighter disclosure, does not cover commercial marketing content, product photos or advertising.

To be honest about this: it is a defensible reading, not settled case law. This is new law with no judicial precedent to date, and its concrete application will depend on the national market surveillance authorities of each Member State.

Penalties: up to €15 million or 3% of turnover

Article 99 places breaches of the transparency obligations in the AI Act's second penalty tier: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Member States set the precise rules, but the regulation requires that penalties be effective, proportionate and dissuasive — and that they take the interests of SMEs and start-ups into account. That is the honest counterweight to the headline figure: proportionality is written into the text, not just promised.

The grace period until 2 December 2026 — a narrow scope

An extra window, until 2 December 2026, does exist — but it is narrower than commonly assumed. It applies only to the machine-readable marking obligation (Article 50(2)), and only for generative AI systems already on the market before 2 August 2026. A system placed on the market after that date must comply immediately, with no grace period. And this window has no bearing on the deployer's disclosure obligation (Article 50(4)), which applies from 2 August 2026 with no calendar exception.

The stripped-C2PA trap — the part nobody explains

C2PA metadata is fragile: a resize or a recompression is usually enough to wipe it out. And that is exactly what happens to almost every product image: as soon as a file is uploaded to a CMS, an e-commerce platform, a CDN or an ad network, it is almost always resized and recompressed — and the C2PA chunk disappears in the process. The image leaves compliant and arrives stripped of its provenance proof, with neither side having done anything wrong.

This is exactly why pixel-level watermarks (of the SynthID type) exist as a complement, not a duplicate: they are designed to survive cropping and compression where C2PA cannot. Merchants should treat the two layers as complementary — not rely on either one alone — regardless of which tool they use to generate their visuals.

How to check an image

Three concrete checks, independent of the tool used:

C2PA credentials
Can be inspected with Content Credentials verification tooling.
The IPTC XMP DigitalSourceType property
Carries the value trainedAlgorithmicMedia for algorithmically generated media.
Inside a PNG file
The C2PA manifest lives in a caBX chunk, and the XMP metadata in an iTXt chunk.

What MannequinIA does

Every image generated by MannequinIA carries a cryptographically signed and timestamped C2PA Content Credential, issued by the generation model's provider (Google Media Processing Services, chaining to the Google C2PA Root CA G3, with an RFC-3161-style trusted timestamp). The file also carries the XMP IPTC DigitalSourceType property with the value trainedAlgorithmicMedia. Our pipeline applies any visible watermark before this marking step, so the marking is not invalidated by later re-encoding. The generation models we use also embed, per their provider's documentation, an invisible pixel-level SynthID-type watermark — a documented property of the upstream model, not something verifiable by inspecting the file. None of this discharges your own obligation as a deployer under Article 50(4): it remains your decision whether, and how, to disclose the AI nature of a visual you publish.

The full detail of our marking is explained on our AI transparency page. AI transparency →

Frequently asked questions

01Am I affected if all I do is remove a background, upscale, or colour-correct?

No, not under the provider's marking obligation (Article 50(2)): these operations qualify as standard editing that does not substantially alter the content or its meaning, and are explicitly exempt. The situation changes as soon as a synthetic model is added to wear the garment: that becomes a substantial alteration, and is covered by the obligation.

02Does this apply to me if I sell into the EU from outside the EU?

The AI Act's obligations generally hinge on where the content is made available — not on where the seller is established — so a non-EU e-commerce seller reaching EU buyers can be affected. This is a general point of scope worth confirming with legal counsel for your specific situation, rather than something settled definitively here.

03Do I have to put a visible label on every product photo?

Not systematically. Article 50(2) requires machine-readable marking (not necessarily visible), and it falls on the AI system's provider. The obligation to clearly disclose to the public — the one that most resembles a "visible label" — only falls on the deployer, under Article 50(4), when the visual qualifies as a deepfake. That is precisely where the grey area sits for a product photo, in the absence of case law.

04What happens to the marking when I upload the image to my store platform?

The C2PA data is likely to be lost: most CMSs, CDNs and ad networks resize and recompress uploaded files, which wipes out the C2PA metadata chunk. The invisible pixel-level watermark, by contrast, is designed to survive that kind of processing — which is why the two layers are complementary rather than redundant.

05What if my images were generated before 2 August 2026?

What matters is not the date the image was generated, but the date the AI system that produced it was placed on the market. If that system was already on the market before 2 August 2026, its provider has until 2 December 2026 for the machine-readable marking part only. This does not change your own obligation as a deployer: if a visual you publish qualifies as a deepfake, the Article 50(4) disclosure obligation applies from 2 August 2026, with no grace period.

06Is the 20 July Code of Practice mandatory?

No, it is voluntary. The European Commission has confirmed it, however, as an adequate means of demonstrating compliance with Article 50, which makes it a useful reference point even without a formal obligation to adopt it.

07Is a fully synthetic AI model itself a deepfake?

A model that resembles no existing real person does not, by itself, meet the definition of a deepfake, which targets resemblance to existing persons, objects, places, entities or events. The risk shifts instead to the product being depicted: a real garment, staged in a photorealistic way, can fall within the "objects" category of that same definition, regardless of how synthetic the model wearing it is.

08What are the concrete penalties for non-compliance?

Up to €15 million or 3% of total worldwide annual turnover, whichever is higher — the second penalty tier under Article 99. Each Member State sets its own enforcement details, but the regulation requires penalties to remain effective, proportionate and dissuasive, and to take the interests of SMEs and start-ups into account.

Sources

This page is provided for information only and does not constitute legal advice. Article 50 is new law with no settled case law; verify your specific situation with qualified counsel before drawing operational conclusions from it.