Skip to content
← Notes

Notes · August 7, 2026

AI-generated images: when you have to disclose, and when you don't

25 min read


This page explains when a piece of AI-made creative has to be disclosed to whoever sees it, and when it doesn't. From 2 August 2026, Article 50 of the EU Artificial Intelligence Act requires a perceivable disclosure on some AI-generated or manipulated content. Not on all of it, and not based on which software you opened: what counts is what the image makes a person believe. If you're short on time, skip to the one question to ask yourself in front of a creative, and to the table of cases.

What the AI Act actually requires for AI-generated content

Article 50 does not say "if you used AI, stick a badge on it". It says two different things to two different parties.

Whoever supplies the system, the provider, has to make the output machine-recognisable as artificial: watermarks, metadata, machine-readable identifiers. That obligation lives inside the product you use, so if you're only using someone else's tool it isn't your job. Supplier doesn't necessarily mean whoever sells it to you — it also covers whoever gives it away for free — and further down you'll see the case where that role becomes yours without you having built anything.

Whoever uses the system to publish something, the deployer, has a tighter and far more visible obligation: when publishing a deep fake, they must disclose that the content has been artificially generated or manipulated. The same applies, in a much narrower case, to text that informs the public on matters of public interest.

The practical difference is right here, and the Commission puts it in writing: whoever publishes cannot simply lean on the machine-readable marking the provider embedded in the file. The technical marker is for machines, the deployer's disclosure is for the person. Content can have its C2PA metadata in perfect order and still be non-compliant, because nobody looking at it has any way of noticing. The Regulation requires the disclosure to be clear and distinguishable "at the latest at the time of the first interaction or exposure".

And here comes the part worth reading twice if you work at an agency, because instinct answers it backwards. The deployer is whoever uses the system under their authority, natural person or legal person alike, and the Commission guidelines give "an advertising company" as their example. The people working inside it, from designers to content creators, are not separate deployers, and neither are contractors and freelancers involved on that company's behalf, under its responsibility and control.

The flip side is the sentence that changes the job: "a company that merely commissions an advertising agency to produce an advertisement, without taking decisions and exercising control over whether and how the advertising agency uses AI in the production process, is not a deployer". If the client says "make me the creatives" and never gets into how you produce them, the deployer is you.

Meta's badge is not your disclosure. The platform detecting AI on its own doesn't close your obligation, at best it sits alongside it.

What counts as a deep fake under the AI Act (it isn't what you think)

In everyday language a deep fake is somebody's face pasted onto another body. The Regulation's definition is much wider and covers objects, places, entities and events: AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

For anyone selling products, that extension changes a great deal. A kitchen that doesn't exist, photographed as though it did, is as much inside the definition as a swapped face. So is a generated model in a realistic hotel room.

The Commission also clarifies that the subject doesn't have to actually exist: it's enough that it resembles "someone or something that exists, can plausibly exist or could have plausibly existed". What stays outside is anything defying the laws of physics or biology, and the official examples are as entertaining as they are clear: a sphinx flying over the Eiffel Tower, mice arguing in human language about cheese inside a commercial. Nobody mistakes those for photographs.

The three elements that matter are always the same: how closely the content resembles something real, whether that thing exists or could plausibly exist, and whether a person could believe it's authentic. An abstract backdrop behind a shoe fails the first and stops there. A photorealistic living room passes the first two, but realism doesn't hand you the third: the guidelines warn that "photorealism alone is not determinative", and it still has to be assessed whether that scene could mislead someone about the authenticity of what they're seeing, in the context where you publish it.

The one question to ask in front of a creative

There's only one test you can actually use at the speed you work when twenty variants need uploading.

If I remove the AI-generated part, does what a person understands about the product or the scene change?

If the answer is no, you're almost always outside: you made decoration. If it's yes, the generated part is carrying information, and the disclosure question opens up.

Take the same package on three different backgrounds. On a flat orange field you learn nothing new about the product. On a laid table you learn what time of day it's used. Inside a suitcase you learn how big it is, and that's a piece of information your product might contradict when it arrives at the customer's door.

Two assets out of the same workflow, same tool, same prompt, can end up one inside the obligation and one outside. That isn't an inconsistency in the rule: the rule looks at the message reaching the viewer, not at the process that produced it.

The cases I run into most often

I use this table as a first filter. The middle column is how Article 50 reads, the third is what I do in practice, which on a few rows is more cautious than the rule strictly requires.

People, voices and video

CaseArticle 50What I do
Fully generated image or video showing apparently real people, products or placesCovered when it could falsely appear authenticDisclose
Generated, realistic testimonial or avatarCovered when it looks like a real or plausible personDisclose
Face swap or body replacement on real footageTextbook manipulationDisclose as partially modified
Lip sync applied to a real personCovered when it makes words never spoken look authenticDisclose
Cloned voice of a real personCovered when the audio passes for a genuine recordingAudible notice, not just written
Synthetic voice that sounds like a human recordingAssessed on the subject representedDisclose in realistic cases
Generated music or audioAI origin alone doesn't create a deep fakeCase by case
Video review attributed to someone who never said itCan be a deep fakeI don't publish it: a label doesn't make a false testimonial lawful

Products and environments

CaseArticle 50What I do
Product or packaging rebuilt with AI from a reference photoHigh risk if it looks like a genuine photograph of the productDisclose
Real product inside a realistic environment never photographedDepends on what the scene addsDisclose if the environment changes how the product is perceived
Real product on a graphic or clearly artificial backgroundGenerally outsideNothing
Shop, home, hotel or venue recreated photorealisticallyCovered when it passes for documentation of a real placeDisclose
Generated person added to a real photo of the venueThe composition looks like a genuinely photographed sceneDisclose
Generated product demonstrationCovered when it looks filmedDisclose
Generated or altered before-and-afterHigh risk of false authenticityDisclose, and re-check the rules on performance claims

Retouching, editing, text

CaseArticle 50What I do
Cosmetic retouching or removing a blemishOutside until meaning or authenticity changesNothing
Colour, light, contrast, digital noise correctionTechnical editingNothing
Crop, resize, format adaptationOutsideNothing
Upscaling and resolution improvementOutside when it doesn't invent detailNothing, but I check what the tool reconstructed
AI used for briefs, copy variants, editingDoesn't trigger the obligation on its ownNothing
Clearly graphic infographic or slideThe required false authenticity isn't thereNothing on the visual side
AI text on an ordinary product pageNo automatic obligationNothing
AI text on a matter of public interest, without human reviewDisclosure requiredDisclose

On borderline cases the table doesn't decide on its own. Resemblance, plausibility, context, audience and the message conveyed all still have to be weighed.

Does an AI-generated background have to be disclosed?

It's the most frequent case in ecommerce and the most argued about, so I'm giving it its own section.

You start from a real photo of the product, cut it out, generate a new backdrop. If the backdrop is a colour, a texture, an abstract shape, the product stays the only information in the creative and nobody believes they're looking at a photograph taken somewhere. You're outside.

When the backdrop becomes a scene, you start telling people things you never photographed: where the object sits, next to what, how big it is, in what context it's used. A cabinet in a realistic living room communicates dimensions. A cream on a marble shelf with the right light communicates a price bracket. A supplement next to a breakfast communicates a moment of use.

The creative has to be read whole, not in layers. If the generated part changes what the customer expects to receive, disclosure is the smaller of your problems: that scene is building you a return.

How the label is made, and where it goes

The Regulation requires a disclosure that is clear, distinguishable and perceivable at the latest at first exposure. Perceivable means it can be seen or heard without doing anything special: no technical tools, no clicking "more", no digging through metadata.

There is no mandatory wording. Simple phrasing works, as long as it tells the truth about what was generated:

  • "AI-generated content"
  • "AI-generated image"
  • "Content partially modified with AI"
  • "Visual elements generated with AI"
  • "AI-generated voice"
  • "Reconstruction made with AI"

On placement I have one rule: the label goes inside the file, every time that's technically possible. Caption, description, hashtags and platform information detach from the creative the moment someone downloads it, forwards it or re-uploads it elsewhere. A caption can be enough in some cases, but it's the fragile link in the chain, and the fragility shows up precisely when the content travels.

For video and audio the operational guidance comes from the code of practice, which is voluntary and whose commitments bind whoever signs it. The law requires the disclosure to be clear and distinguishable at first exposure, and to meet the applicable accessibility requirements. The code says how to do that in practice, and it's worth following anyway because it's the simplest way to show you did things properly.

In video the icon goes at the beginning, then repeated at regular intervals where possible, at a minimum after interruptions such as an ad break. It's needed because a person can join the video halfway, and because a screenshot or a clipped fragment keeps travelling on its own. In audio you put a spoken notice at the start, in plain language, in the language of the content or in English: a caption on something people listen to isn't perceived by anyone.

One last thing nobody does and that costs ten seconds: archive the labelled version. The day you have to prove the label was there, you're the only evidence.

The EU icons: which ones exist, and how big they have to be

There is an official icon set, published by the Commission and free to download. There are three, and they say different things.

IconNameWhen to use it
EU base icon for AI-generated contentBase iconWhen AI was involved in creating the deep fake or the published text, or when you pair it with your own text label or an interactive second layer
EU Fully AI-Generated iconFully AI-GeneratedWhen the content is entirely AI-generated, with no human-created elements and no human editorial control beyond prompting
EU Partially AI-Modified iconPartially AI-ModifiedWhen pre-existing, human-made content was partially modified with AI, to the point of becoming a deep fake or text on matters of public interest

The example the Commission gives for the third one is precise and it concerns you: an authentic photograph of an empty apartment, furnished with AI.

The icons download as SVG and PNG, in four variants: black, white, black at 50% transparency, white at 50% transparency. They're free, and you don't have to credit the Commission to use them.

Two clarifications that remove the most common misunderstanding. Using the icons is optional, disclosing is not. And putting the icon on doesn't make you compliant by itself: responsibility for a compliant disclosure stays with the deployer.

There's also a user-testing result that works as copy guidance: the base icon performs better across all measures when it's accompanied by a word. Icon plus "modified", not icon on its own.

How big does the icon have to be

There is no pixel measurement, and anyone giving you one made it up. The code of practice the icons belong to says the icon "may appear in different sizes depending on the context", as long as the disclosure stays clear and distinguishable.

What the code does fix is the shape, not the size, and it binds whoever signed it:

  • the main visual element is the capitalised acronym AI, in English (in the national language only where English is incompatible with national rules on language use)
  • the two letters must have the same height
  • if you resize it, the letters' proportions must be preserved
  • colour, contrast and typeface are free, as long as it stays readable and recognisable

On placement the guidance is operational: somewhere no overlay element covers it, the top right corner of the image or video as the example, inside the file unless you have an equivalent alternative, spaced away from other notices and legible against any background.

Since no measurement exists, here's the one I use, which is my own convention and not a rule: on a 1080×1080 square I keep the icon around 80 px per side with a 40 px margin from the corner, and on a 1080×1920 story I keep it clear of the first 250 px and the last 400, where the Instagram interface eats everything. The real criterion is just one: look at it on a phone, at arm's length, without zooming. If you have to lean in, it's small.

Does AI-written text have to be disclosed?

Almost never, and the version doing the rounds is far wider than the rule.

The obligation on text covers AI-generated or manipulated content published with the purpose of informing the public on matters of public interest. Public interest doesn't mean "interesting". The Commission's answers on Article 50 give these examples: politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, and economic, financial, political, scientific or cultural developments.

A description of a pair of shoes written with a model doesn't become content requiring disclosure, and the guidelines put exactly "AI-manipulated text that is part of a company's advertisement or product descriptions" among the examples that stay outside. There is a parenthesis on that line, though, and it's the part you need to keep: outside on condition that it carries no claims about health, consumer safety or sustainability.

It's a distinction you can see at a glance on your own catalogue. A sneaker's product page stays outside. The same page explaining why that material is safer for a child, or how recyclable that packaging is, changes category. Anyone building a disclosure procedure across three thousand product pages is spending time on an obligation they don't have, while not looking at the handful of pages that genuinely carry it.

Then there's the exemption for anyone publishing seriously: if the generated text goes through human review or editorial control, and a natural or legal person takes editorial responsibility for the publication, no disclosure is due.

What counts as human review

Not a tick box. The Commission separates two things. Human review is the deliberate examination of the substance of the content by one or more natural persons with relevant knowledge and professional judgement. Editorial control is what a responsible editorial entity exercises in practice — an editor-in-chief, say — with authority to approve, alter or reject the substance of what goes out.

On the line that matters to most companies the Commission is blunt: superficial, solely formal or procedural checks, such as spell-checking or grammatical correction, do not count as human review.

Running text through a grammar checker is not review. Fixing typos isn't either. Nor is an editorial policy that exists on paper, an automated check, or approval given in a hurry without engaging with the substance.

There's also a minimum the guidelines state explicitly, and that almost nobody in an in-house team writes down: fact-checking has to be part of the review. Reading the substance and approving it as it stands is fine, provided the person doing it knows the subject and provided the facts have been checked. Review doesn't require changing anything, it requires having assessed, and having the competence to assess.

For a company the difference shows up practically. If nobody can say who read that text before it went out, the exemption isn't there, because nobody took responsibility.

The obligation nobody mentions: chatbots

The whole conversation has focused on images, while Article 50 opens with an obligation that is far more widespread in marketing: a person has to know they're talking to an AI system, unless it is obvious to a reasonably well-informed, observant and circumspect person looking at the context.

WhatsApp assistants, automated replies in Instagram DMs, quote bots on the site, agents qualifying leads overnight. If yours says "Hi, I'm Giulia from support" and nothing else, that sentence is working against you.

Watch who's on the hook. In the text the chatbot obligation falls on the provider, not the deployer, and it looks like something for whoever builds the models. Except the Regulation also defines as a provider anyone who "has an AI system developed" and puts it into service "under its own name or trademark". What matters is whose name sits on the bot. If it's yours, the assistant you resell to clients under your own brand, you're the one who risks taking that role on. If it's the client's, the provider becomes them, and they had better know it beforehand: it's a line for the contract, not a discovery for later. Either way it's worth spending real legal advice on.

Staying out of it is cheap: one line in the first message, "you're talking to the automated assistant, say the word and I'll pass you to a person", and you've also solved a conversion problem.

Creatives made before 2 August 2026

The Commission says it in one line: content generated before 2 August 2026 does not need to be labelled retroactively. It adds, though, that it encourages deployers to do it anyway where possible.

Note the word it uses: generated, not published. The dividing line is when the file was born, not when it's running. An ad created in June that's still delivering today stays outside the obligation.

Which doesn't make me leave it at that. Labelling an asset that's already live costs one line at upload time, and it spares you having to reconstruct in six months which variant was generated when, with the agency changed and the drive full of files called final_v3_ok. The Commission's invitation to do it anyway isn't polite rhetoric, it's the advice of someone who knows how those archives end up.

On the rest there's no doubt: if after 2 August you regenerate, modify with AI or produce a variant, that output is new and gets assessed from scratch.

Another date going round that doesn't concern you is 2 December 2026. It applies to providers, on systems already placed on the market before 2 August, and it covers the technical marking of the output. It doesn't move the deployer's obligation by a single day.

Before the AI Act, another rule already covers this

Anyone bracing for European penalties often isn't looking at the rule that has covered exactly this kind of creative for much longer.

A creative that makes a cabinet look bigger than it is, a garment fall differently than it does, an environment the product has never seen, is a potentially misleading commercial practice under Directive 2005/29/EC on unfair business-to-consumer commercial practices. It has been transposed in every member state, and each one enforces it through its own consumer authority — in Italy the AGCM, in Spain the consumer bodies of the autonomous communities — or the central government's, once the harm spreads across several of them — elsewhere again differently. It didn't just enter into application like Article 50: it has been there for years, and it covers precisely the point where a generated scene tips over — how the product is represented to whoever will buy it.

And here's the part that interests me most: an AI label does not cure deception. Writing "AI-generated image" under a photo that misrepresents the product answers, at best, the question about where the content came from, and leaves you exactly where you were on the representation. They're two different checks, and the second one is the one that gets you returns.

What's at stake

Article 99 of the Regulation provides, for breaches of the Article 50 transparency obligations, administrative fines of up to 15 million euro or, for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

For SMEs, including start-ups, the mechanism inverts: whichever is lower between the percentage and the fixed amount. It's the only line in this article where being small helps, and it's worth knowing because the "up to 15 million" headline gets repeated to people turning over two million who will never see it.

That "up to" carries everything else. The actual amount depends on the case, the gravity, the duration, the conduct and the proportionality criteria the national authority has to apply. Reading these numbers as an imminent threat to a small ecommerce is a scale error; using them to justify the fact that a disclosure costs ten minutes is reasonable.

The workflow I use at the agency

The hard part isn't understanding the rule, it's remembering it on the twentieth creative on a Friday. So I don't remember it: I put it into the approval process.

For every asset I keep four pieces of information, in a column of the same sheet where I already log the variants: what type of content it is, whether it's fully generated or only modified, which elements are real, which are synthetic.

Then the test question, the one about removing the generated part. If it passes, the asset ships as it is. If it doesn't, I pick the wording, put it inside the file, fill in the platform flag too if there is one, and save the labelled version where the original lives.

For material arriving from outside I do the same, and I ask the supplier up front and in writing: which tool did you use, on which part, to do what. A creator sending you a video isn't transferring the problem to you, they're handing it over along with the file.

Frequently asked questions

Since when does the obligation to disclose AI-generated content apply? Since 2 August 2026, the date Article 50 of Regulation (EU) 2024/1689 became applicable. The provisions on penalties have applied since 2 August 2025, so since 2 August the obligation and the enforcement apparatus have been operating together.

Do I have to badge every image made with AI? No. The deployer's obligation covers content that falls within the deep fake definition, meaning content resembling real or plausible people, objects, places or events that a person could mistake for authentic. An abstract backdrop or a clearly graphic infographic stay outside.

Does a real product on an AI-generated background have to be disclosed? It depends on what the background does. If it's graphic or abstract and doesn't change what you understand about the product, generally no. If it's a realistic environment communicating dimensions, context of use or qualities the product doesn't have, disclosure has to be considered seriously.

Does text written with ChatGPT have to be disclosed? Only if it's published to inform the public on a matter of public interest, and only if it hasn't gone through human review or editorial control with a natural or legal person taking editorial responsibility for the publication. The Commission guidelines put product descriptions and advertising copy among the examples that stay outside, on condition they carry no claims about health, consumer safety or sustainability.

Is it enough to say in the caption that the content is AI-generated? It can be enough in some cases, but it's the most fragile option: captions and metadata separate from the content when it's downloaded or reshared. Where technically possible, the disclosure goes inside the file itself.

Does Meta's AI content flag replace the disclosure? No. A platform flag, automated detection or technical metadata do not in themselves replace the deployer's obligation. Fill them in where required, as an additional control.

Who is responsible when an agency produces the creatives? The deployer is whoever uses the system under their authority, natural person or legal person alike, and the Commission guidelines give an advertising company as their example. The people working inside it and freelancers involved on its behalf are not separate deployers. A client who merely commissions the ad, without deciding whether and how the agency uses AI, is not a deployer: in that case the role belongs to the agency. If instead the client sets how it's produced, it goes back to them.

Do I have to say my chatbot is an artificial intelligence? The obligation in Article 50(1) falls on the system's provider, not on whoever uses it, and applies unless interacting with an AI is obvious to a reasonably well-informed person from the context. The point is who you are in that chain: if you switch on a WhatsApp assistant or a social bot with your name on it, that role can land on you. When in doubt write the line anyway, it costs one sentence.

Do creatives made before 2 August 2026 have to be labelled? No. The Commission writes that content generated before 2 August 2026 does not need to be labelled retroactively, and encourages doing it anyway where possible. The dividing line is the generation date, not the publication date, so a campaign created earlier and still delivering stays outside. If instead you regenerate or modify the content after that date, the output is assessed as new.

Is there an official icon for AI-generated content? Yes. The Commission has published three icons: a base one, "Fully AI-Generated" for entirely generated content and "Partially AI-Modified" for pre-existing content partly modified with AI. They download free as SVG and PNG, in four colour variants, with no attribution required. Using them is optional and does not on its own demonstrate compliance.

How big does the AI icon have to be? There is no mandatory pixel size. The code of practice says the icon may appear in different sizes depending on the context, as long as the disclosure stays clear and distinguishable. What the code does fix, for those who sign it, is the shape: the acronym AI in capitals, both letters the same height, proportions preserved when resized.

Are the EU icons mandatory? No. Using the icons is optional, disclosing content when the Article 50 conditions are met is not. Adding the icon does not on its own demonstrate compliance: the disclosure still has to meet the requirements of the rule.

What's the penalty for not disclosing an advertising deep fake? Up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher; for SMEs and start-ups, whichever is lower. These are ceilings, not automatic amounts.

Changelog

7 August 2026: first published. Every statement about who is on the hook, about the scope of public interest, about human review, about content predating 2 August and about the icons is checked against the Regulation, the European Commission's answers, the guidelines on Article 50 and the code of practice on the transparency of AI-generated content.

Read next

DC

Davide Cosmai

Meta Ads Expert & Growth Strategist · Meta Business Partner. 15+ years running Meta campaigns. €52M+ in revenue generated for clients.