The EU AI Act and E-commerce Imagery: What Does AI Transparency Actually Look Like?

The EU AI Act's transparency rules are now in effect, but what does disclosure actually look like for e-commerce imagery?

If you use AI somewhere in your e-commerce content workflow, there is a deceptively simple question you may now be asking: Do we need to label this?

Unfortunately, the equally simple answer is: it depends. Because while the rules exist, applying them to real e-commerce content has proven to be not so straightforward.

That was one of the main takeaways from a recent conversation with media lawyer and digital and AI expert Kelsey Farish about the EU AI Act and what its transparency rules could mean for brands creating content.

The EU AI Act's transparency provisions came into effect on August 2, 2026, but for many e-commerce teams, the questions are only just beginning.

Does an AI-generated model need a label? What about an AI-generated background? If AI was only used to retouch a real photograph, does that count? Does the label need to sit directly on the image? And what happens when the product itself is completely real, but everything around it was generated?

There are answers to some of these questions. There are also quite a few grey areas. And that is probably the most important place to start.

First: Does the EU AI Act Apply to You?

The EU AI Act may be European legislation, but that doesn't mean only European companies need to pay attention to it.

One of the important things about the Act is how far its reach can extend. A company does not necessarily need to be headquartered in the EU for the rules to become relevant. If AI-generated or manipulated content is being shown to people in Europe, there is a good chance the regulation needs to be part of the conversation.

As Kelsey put it: "You go into the European Union, you play by the European Union's rules."

That becomes relevant for e-commerce, where content production rarely happens in one place. Your creative team might be in New York, your post-production team somewhere in Asia, and your technology provider based somewhere else entirely. But if the final content ends up on a PDP viewed by shoppers in Europe, EU regulation applies then.

That's why the EU AI Act is worth understanding even if your company would never describe itself as a "European brand." In a global e-commerce workflow, where the content is created matters less than where it ultimately ends up.

What Does the EU AI Act Actually Say About Disclosure?

Article 50 is the part of the EU AI Act that becomes especially relevant when discussing the labeling of AI-generated and manipulated media.

Broadly speaking, deployers of AI systems that generate or manipulate certain image, audio, or video content are required to disclose that the content has been artificially generated or manipulated.

Two words matter a lot here: Deployer and disclose.

A deployer is essentially the person or company using the AI system.

For most brands, retailers, studios, and content teams, the deployer category is the more relevant one. If your team is using generative AI, synthetic models, background generation, or similar tools as part of commercial content production, then the question becomes what responsibility you have to make that AI use understandable to the people seeing the result. That's where the Act says disclosure should be provided in a clear and distinguishable manner, generally by the time someone first encounters the content.

This is also why machine-readable metadata and consumer-facing disclosure should not automatically be treated as the same thing. Technical provenance can tell another system how an asset was created, but that does not necessarily mean the shopper understands what they are looking at.

What Counts as a "Deep Fake" Under the EU AI Act?

This is one of the stranger parts of the legislation for anyone coming from photography, fashion, or e-commerce.

When most people hear "deepfake," they probably think of a fake video of a politician, actor, or celebrity.

The EU AI Act uses a much broader definition.

Its definition can include AI-generated or manipulated image, audio, or video content that resembles existing people, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful.

So yes, potentially, we are talking about more than synthetic celebrities. A product image can enter the conversation too.

As Kelsey pointed out during the discussion, that can feel unintuitive.

"I wouldn't take a picture of a handbag, manipulate it and be like, 'This is a deepfake Prada bag.'"

And yet, the law has intentionally cast a wide net. For e-commerce teams, the practical takeaway is not necessarily to start calling every generated product image a deepfake internally. It is that the transparency rules may apply much more broadly than the everyday meaning of the word would suggest.

The EU AI Act Takes a Risk-Based Approach

One thing that can get lost in conversations about AI regulation is that the EU AI Act does not treat every use of AI as equally risky.

It takes a risk-based approach, which is an important distinction for e-commerce teams.

The potential consequences of AI being used incorrectly in a medical system, hiring process, or biometric tool are clearly very different from using AI to generate a new background for a handbag.

That doesn't mean e-commerce gets a free pass. It means context matters.

Kelsey described the approach as being "proportionate to risk and context," which is also a useful way to think about AI governance more broadly.

Rather than stopping at Was AI used?, a more useful question may be: What did the AI actually change, and what impact could that change have on the person viewing the content?

A generated background that leaves the product itself untouched may raise one kind of transparency question. But if AI changes the color, fit, shape, material, or construction of the product a shopper is considering buying, the stakes are very different.

Because in e-commerce, visual accuracy is not just about whether an image looks good.

The image is part of the product information that a shopper is using to make a decision.

Is "AI-Generated" Actually Enough of a Label?

As hybrid workflows become more common, a simple "AI-generated" label may sometimes create more confusion than clarity.

A single PDP image might contain a real product, a synthetic model, an AI-generated background, traditional retouching, AI-assisted cleanup, and final human post-production. Calling the entire thing "AI-generated" does not tell the shopper which elements are synthetic and which still represent the physical product.

That is why more specific wording may be more helpful in some cases. A label such as "AI-generated background" tells the viewer something concrete, while still making it clear that the product itself is real. Likewise, "synthetic model" communicates something very different from simply saying "AI-generated image."

Kelsey made this point directly when discussing a real handbag placed into a generated environment:

"By saying 'AI-generated background' as the label, I'm giving the consumer more words, more context."

That may turn out to be one of the more important principles for e-commerce transparency. As the technology becomes more embedded in production, disclosure may need to become more descriptive rather than more generic.

Where Does the Disclosure Need to Appear?

The Act refers to disclosure being made by the time of a person's first interaction or exposure to the content.

For e-commerce, that creates a practical problem.

Imagine an AI-generated campaign image appears on a category page, but the only disclosure sits inside the product description on the PDP. By the time the shopper sees that note, they have already encountered the image.

The same issue applies across other channels. An image might first appear in paid media, email, social, search, or a campaign landing page before the shopper ever reaches the product page.

That is why AI transparency cannot necessarily be treated as something that lives only in product copy or legal terms. Brands need to think about the full journey of an asset and where the customer actually encounters it first.

There is also no single universal label that every brand is required to use. The challenge is less about choosing one specific sticker and more about making sure the disclosure is clear enough for the person viewing the content to understand what has been artificially generated or manipulated.

Are Metadata and AI Labels the Same Thing?

Which brings us to the distinction between machine-readable marking and consumer-facing labeling.

AI technology providers may have obligations around making generated outputs identifiable in machine-readable ways.

That can include metadata, provenance information, or technical standards designed to help systems recognize that AI was involved.

But that does not automatically solve the brand's transparency responsibility.

As Kelsey explained, there is a difference between making something machine-readable and making it understandable to the person actually viewing it.

Metadata might tell another system how an asset was created. A shopper usually cannot see that.

For brands acting as deployers, the bigger question is often how the information becomes perceptible and understandable to the consumer.

In other words: Metadata is not necessarily a substitute for communication.

Is Labeling the Only Thing Brands Need to Think About?

No, technically not. Transparency is one part of the picture, but when AI is used to alter a real person, reuse their likeness, change their clothing, or create new content from older campaign imagery, separate questions can arise around consent, contractual rights, performer protections, and intellectual property.

An AI disclosure does not solve those issues. An image can be clearly labeled and still use someone's likeness in a way they never agreed to.

For brands working with real models, performers, as Digital Twins/AI Twins, that means AI governance needs to go beyond deciding where a badge appears. It should also cover what can be changed, when consent is required, what needs human approval, and who gets the final say before an asset goes live.

What Brands Can Do Now

There are still open questions in the regulation, but that does not prevent brands from building better processes now.

A useful place to start is simply mapping where AI appears in the content workflow. That means looking beyond obvious generative tools and including AI features embedded in retouching software, model generation, background replacement, video production, and other creative systems.

From there, teams can classify what AI is actually changing. Is it the product, the person, the environment, or only minor cleanup? They can then look at where the asset appears, where a shopper encounters it first, and whether a generic disclosure would actually explain what happened.

It is also worth setting internal rules before waiting for perfect external guidance. That might include deciding which uses of AI require approval, what can never be altered without consent, when human review is mandatory, and how the team wants to handle disclosure across different channels.

The goal is not to create the perfect policy overnight. It is to make sure the use of AI is intentional rather than accidental.

The Uncertainty Is Real, But That Does Not Mean Do Nothing

There are still plenty of questions that do not have definitive answers yet.

How much AI-assisted editing is enough to trigger a disclosure? What design will regulators eventually consider sufficiently clear? How much can a site-wide AI statement do on its own? And how consistently will any of this be enforced across millions of commercial images?

Those questions will become clearer over time as guidance develops and enforcement begins.

Kelsey was refreshingly direct about that uncertainty:

"If you come across a lawyer who says that they know all the answers, please just turn in the opposite direction and run."

For now, the most useful thing brands can do is understand where AI sits in their production process, identify the places where it can materially affect a shopper or a real person, and build a framework that can evolve as the rules become clearer.

AI is already embedded in e-commerce content production. The next step is making sure the processes around it are just as considered.

This article is for general informational purposes only and does not constitute legal advice.

5 Takeaways from the EU AI Act for E-commerce Teams

Read more →

EU vs. U.S. AI Regulation: What E-commerce Brands Should Know

Read more →