EU AI Act and AI Images: What Creators Actually Have to Label

The story circulating in agency Slack channels is that European AI regulation was pushed back. You can relax, the argument goes, because Brussels hit the brakes on compliance deadlines until late 2027.
That belief is wrong, and relying on it is expensive. The Digital Omnibus (Regulation (EU) 2026/1744) deferred high-risk AI system deadlines, but it left Article 50 untouched. Transparency rules for AI-generated images have applied across the EU since 2 August 2026. If you generate or publish synthetic visuals that reach European users, the obligations are active today.
Here is what you actually need to know: the law splits responsibility down the middle. AI generator tools carry the machine-readable metadata duty, while you—the creator, brand, or agency publishing the image—carry the visible disclosure duty whenever an image looks deceptively real. Abstract art gets a pass; photorealistic product mockups do not.
Below, we break down your exact obligations under the European Commission's final Article 50 Guidelines (C(2026) 5054 final) across six clear sections:
- What changed on 2 August 2026 (and why the Digital Omnibus did not save you).
- The provider versus deployer obligation matrix.
- The deepfake test: why synthetic product shots are caught.
- The narrow creative exception and marketing imagery.
- Real-world provenance: why social platforms strip your metadata.
- Penalties, national regulators, and your immediate compliance checklist.
What changed on 2 August 2026
When the European Union passed Regulation (EU) 2024/1689, it established a phased timetable. General-purpose AI rules arrived in 2025. Then, on 2 August 2026, Article 50 came into force.
When the Commission proposed the Digital Omnibus on AI to ease administrative drag, many assumed all deadlines moved. But when Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026, it deferred standalone Annex III high-risk systems to 2 December 2027 and embedded systems to 2 August 2028. Chapter IV transparency rules remained anchored on 2 August 2026.

The Digital Omnibus moved high-risk dates, but Article 50 transparency stayed firmly on 2 August 2026.
There is only one transition window in play: generative AI systems that were already on the market before 2 August 2026 have until 2 December 2026 to wire up machine-readable marking. For deployers publishing deepfakes, there is no transition window at all. The duty to disclose realistic synthetic content started the day the rule took effect.
The final Guidelines brought one vital clarification on retroactivity: the rule applies by the date of generation, not the date of publication. If you generated an asset on 15 July 2026 and published it on 10 August, you do not need to add an Article 50 label. If you generated it on 3 August 2026, you do.
Who must label: provider vs deployer
To understand your legal exposure, you must know your statutory role. The EU AI Act defines two distinct actors:
- The Provider (Article 3(3)): The entity that develops an AI system and places it on the market under its own brand (such as Google, OpenAI, Recraft, or JammyJar). Providers must mark outputs in a machine-readable format.
- The Deployer (Article 3(4)): The business, agency, or independent professional using the AI system to produce content. Deployers must display human-visible disclosures when publishing deepfakes.
Under Commission guidance, individual employees and freelance contractors acting on behalf of a client are not separate deployers. The legal person—the brand or agency commissioning and publishing the campaign—carries the regulatory risk.
Situation | Article | Role Bound | Required Action | Core Carve-Out |
|---|---|---|---|---|
Generating synthetic images | Art 50(2) | Provider | Embed machine-readable marks (C2PA, watermarks) | Pre-August 2026 systems exempt until 2 Dec 2026 |
Publishing realistic synthetic scenes | Art 50(4) | Deployer | Display a prominent, human-visible label | Obvious illustration or fantasy styles |
Publishing AI product staging | Art 50(4) | Deployer | Add clear visual or textual disclosure | Purely assistive background cleanup (Recital 134) |
Publishing public-interest synthetic text | Art 50(4) | Deployer | Disclose artificial origin | Human held full editorial control and sign-off |
Generating abstract vector graphics | Art 50(4) | Deployer | No visible label required | Stylised art does not deceive authentic perception |
Notice the practical split: machine-readable watermarking is your software vendor's problem; human-visible labeling on the published post is yours.
Is your image a "deepfake"? (The three-part test)
Most creators assume "deepfake" only applies to political propaganda or swapping celebrity faces onto foreign bodies. Under the AI Act, that assumption will land you in trouble.
Article 3(60) defines a deepfake as any AI-generated or manipulated image, audio, or video that "resembles existing persons, objects, places, entities or events" and would falsely appear authentic or truthful to a reasonable viewer. The word objects is the critical piece.

Under Article 3(60), photorealistic synthetic objects face the exact same test as synthetic faces.
The European Commission applies three cumulative criteria to decide if an image needs a deployer label:
- Resemblance: Does the image portray something with sufficient detail that a viewer maps it to reality?
- Existing or plausible subject: Does it depict an actual person, a real geographical location, or a commercial physical product that exists (or could plausibly exist)?
- Deceptive authenticity: Would an ordinary consumer seeing the visual in context believe it was captured with a traditional camera?
If you generate a hyper-realistic scene of a running shoe splashing through a puddle to use in an ad campaign, that image meets all three criteria. Even if the shoe model is synthetic, it depicts a physical object in a realistic photographic style. It requires a visible label. Conversely, if you generate a flat vector mascot or a 3D isometric clay icon, no viewer mistakes it for a photograph. Stylised illustrations are not deepfakes under Article 3(60), so they need no visible tag.
If you are sorting commercial permissions across jurisdictions, we broke down whether you can use AI-generated images commercially in 2026 alongside ownership rules.
The narrow creative exception and marketing imagery
Creative teams frequently point to Article 50(4)'s exception for "evidently artistic, creative, satirical, fictional or analogous works." The argument goes: our ad campaign is creative storytelling, so we can skip the badge.
Regulators have shut that door. Julia Apostle, partner at Orrick in Paris, noted in her analysis of the final Guidelines that the creative exemption does not eliminate disclosure: it merely allows you to relocate it to places like project credits so you do not break the aesthetic enjoyment of a film or artwork.
In commercial advertising, the Commission's final Guidelines state that commercial promotions generally do not benefit from the reduced creative regime. Legal analyses from both Baker McKenzie and Bird & Bird arrive at the same conclusion: marketing content is not exempt simply because an art director designed it. If an advertisement uses realistic synthetic scenes to pitch a product or service to EU consumers, a visible indicator (such as a corner tag or clear caption note) must be present.
What tools and platforms do (and what they break)
Under the Code of Practice approved by the Commission, model providers are expected to use at least two marking layers on generated assets: digitally signed cryptographic metadata (like C2PA Content Credentials) and an imperceptible embedded watermark (like Google's SynthID).
In an ideal workflow, the generator embeds the provenance data, the publishing tool preserves it, and the social platform surfaces an automatic badge to viewers. In practice, that pipeline breaks on day one.

Metadata strips easily upon export and upload. Your visible deployer disclosure is what holds up.
Major platforms handle provenance inconsistently. LinkedIn and TikTok read and preserve C2PA manifests, displaying platform-level AI badges. But Instagram, Facebook, Threads, and X frequently strip file metadata upon upload during image compression. OpenAI explicitly warns users that C2PA metadata in GPT Image downloads can easily be lost when edited or processed through standard web apps.
Watermarking algorithms fare better against compression, but they are not invincible. DeepMind researchers reported in arXiv:2510.09263 that SynthID achieved a 99.72% true-positive detection rate across standard transformations. Yet independent security researchers Kassis and Hengartner demonstrated at IEEE S&P 2025 that adaptive attacks ("UnMarker") reduced state-of-the-art watermark detection rates down to 43%, concluding that imperceptible watermarks alone cannot guarantee provenance defense.
Because metadata washes off easily in production workflows, you cannot rely entirely on your software provider to keep you compliant. The visible label you add to the finished creative is your only bulletproof safeguard.
Inside JammyJar, multi-model workflows route prompts across GPT Image, Gemini, and Recraft while maintaining Swiss-hosted, privacy-conscious data practices. This keeps your generation histories, prompt logs, and original exports organised in a single workspace should you ever need to demonstrate compliance to a client or auditor.
Penalties, regulators, and national rules
Many agency presentations warn clients about "€35 million or 7% of worldwide turnover" fines for unlabeled AI images. That number is wrong. That top tier applies exclusively to Article 5 prohibited practices, such as social scoring or biometric mass surveillance.
Transparency infringements under Article 50 fall squarely under Article 99(4):
- Maximum penalty: Up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
- SME and startup protection: Small and medium-sized enterprises pay the lower of the two amounts rather than the higher.
Enforcement is handled by national market surveillance authorities across each EU member state, rather than a central Brussels police force. In Germany, the draft KI-MIG designates the Federal Network Agency (BNetzA) as lead authority. In Italy, Law No. 132/2025 establishes domestic supervisory roles with implementing decrees landing by 10 October 2026. Spain approved its draft Organic Law on AI governance in May 2026, giving enforcement teeth to AESIA.
Whether you operate from Madrid, London, or New York, the rules apply to you if your content is distributed to EU consumers. The AI Act has explicit extraterritorial scope under Article 2(1)(c): non-EU deployers are bound whenever their system output is used within the EU market.
Frequently Asked Questions
Do I have to label AI-generated images in the EU? You must label AI-generated images if they are photorealistic and could reasonably deceive viewers into believing they depict authentic people, real products, or real events. Purely stylised graphics, abstract vectors, and obvious fantasy art do not require visible consumer disclosures under Article 50(4).
Does the EU AI Act apply to businesses outside Europe? Yes. The regulation has extraterritorial reach under Article 2(1)(c). If a business based in the United States or the UK publishes AI-generated images targeting or accessible to consumers within the EU, that business must follow Article 50 disclosure rules.
What is the penalty for failing to label an AI image? Violating Article 50 transparency obligations carries fines under Article 99(4) of up to €15 million or 3% of global annual turnover, whichever is higher. For small and medium-sized enterprises (SMEs), statutory penalties are capped at the lower of those two figures.
The creator checklist
Before you hit publish on your next campaign, step through three simple operational checks:
- Run the realism check: Is the asset photographic? If a reasonable customer would think a camera captured the scene, plan for a visible label.
- Pick your disclosure method: Add an on-canvas tag (such as "AI Generated"), include a clear disclosure in the post caption, or use platform-native AI content tags on TikTok and LinkedIn.
- Log generation provenance: Save your raw generation parameters, model versions, and source files in a shared workspace so your team can verify when and how an asset was created.
Start by auditing the images scheduled in your marketing queue this week. Flag the photorealistic scenes, add clean disclosures where needed, and keep your creative pipeline safe.