November 3, 2020
360 product photography: the complete guide
A complete guide to 360 degree product photography. Get info and tips on 360 spin product photography, 360 product photography equipment, and software.
Since August 2, 2026, the EU AI Act requires a disclosure label on AI-generated and AI-changed images that could pass as real. Here is what counts, what is exempt, and what a product photography team should do about it.

Table of contents

If your team uses AI anywhere in your product photography workflow - a generated background, a virtual model, an AI retouch - you now have a new legal duty to think about. Since August 2, 2026, the EU AI Act (the Artificial Intelligence Act) requires a disclosure label on AI-generated and AI-changed images that could pass as real. This piece of AI regulation is part of the EU's push for human-centric AI and trustworthy AI that protects people's fundamental rights across all kinds of AI applications, not just product photos. The rule is not aimed at everyday editing, but it is specific about where the line sits, and the fines for getting it wrong are significant.
This guide walks through what counts, what does not, and gives practical examples of what a product photography team can do to stay on the right side of it.
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) says that any AI-generated or AI-changed image that could look real must carry a machine-readable disclosure. This label must be easy to detect. The rule started on August 2, 2026. It does not apply to normal photo editing. It applies to content that shows something a camera never actually captured.
The EU AI Act, formally the Artificial Intelligence Act, is the European Union's law for artificial intelligence technologies. It was adopted by the European Parliament as Regulation (EU) 2024/1689 in 2024, published in the Official Journal, and it entered into force soon after. It is being rolled out in stages through 2028. The EU AI Act sets four risk categories, using a risk-based approach so that legal obligations for AI developers and deployers of AI systems scale with the risk an AI system poses to people's safety and fundamental rights. This EU regulation does not cover AI used purely for national security or scientific research.
| Risk level | Start date | What it covers | Relevant to product photography? |
|---|---|---|---|
| Unacceptable risk (banned) | February 2, 2025 | Prohibited AI practices, such as manipulative AI, social scoring, mass facial-image scraping, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, and AI that exploits a person's age, disability, or socio-economic status | No |
| High risk - stand-alone AI systems (Annex III) | December 2, 2027 | High-risk AI systems used in hiring, credit scoring, law enforcement, migration and border control management, critical infrastructure, and AI that could affect elections and democratic processes | No |
| High risk - AI inside a regulated product (Annex I) | August 2, 2028 | AI built as a safety component into products that already follow EU product-safety rules, such as medical devices and machinery | No |
| Limited risk (transparency) | August 2, 2026 | AI that creates or changes content, or talks directly to people | Yes - this is Article 50 |
| Minimal risk | No required rules | Everything else, including most AI systems and applications like AI-enabled video games | Most everyday photo editing |
General-purpose AI models and general-purpose AI systems - the large models that power many downstream tools - sit alongside this risk ladder under their own rules, with extra duties for the few that pose systemic risks.
The two high-risk dates changed. They moved from the original December 2027 date after a new rule, Regulation (EU) 2026/1744 (known as the "AI Omnibus" or the "Digital Omnibus on AI"), pushed them back, partly to support innovation while the market adjusts to the new AI rules. Article 50 was not affected by this change. It has applied since August 2, 2026, with no exceptions. (source)
Day-to-day AI governance under this EU AI law sits with national competent authorities in each EU country (also called national authorities), working alongside EU-level bodies such as the AI Office and the European Artificial Intelligence Board. This layered structure is part of the wider body of EU law that shapes how AI is built and used across the EU market.
Article 50 says that when an AI system creates or changes an image, sound, or video so it could look real, the result must carry a mark. This mark must say the content is AI-made or AI-changed, and it must be readable by machines. Certain AI systems - those that generate or manipulate content, or that talk directly to people - carry this transparency duty throughout their life cycle, no matter which risk tier they otherwise sit in. The European Commission's guidance sets out two duties:
The main question the Commission asks is simple: does the image show something that really happened, or does it add something that did not happen? A real product photo, color-corrected and cropped, still shows the real object. It is not affected. But a photorealistic model wearing that product, created from nothing, is affected - even though the model is not a real person.
Before you check an image against the rules below, ask one question: what did the AI actually do to it?
Not for the disclosure rule itself. There is a separate transition period until December 2, 2026. But it only covers one thing: the technical marking that AI providers must add to systems that were already on the market before August 2, 2026 (see "How is AI-generated content technically labeled?" below). It does not delay the deployer's duty to tell viewers about AI-made or AI-changed content. That duty has applied since August 2, 2026. If you publish or re-publish content after that date, you need to check it again - no matter how old the tool is.
These do not need a disclosure label under Article 50:
If a business photographs the real product and edits the image so it still shows that same product correctly, Article 50 does not apply.
You need to disclose when the image adds something that was not really there:
These sit in a gray area. Each case needs its own judgment:
Common advice in the industry is: when in doubt, add the label. An extra label costs little. A missing label, when one was needed, is what causes real trouble.
For content to count as a deepfake under the Act, it usually needs all three of these things at once, not just one:
If even one of these is missing - for example, the content is clearly a fantasy image, or it does not resemble anything real - it is usually not a deepfake under this rule. But it may still need a label under the general rule above, if it could still mislead a viewer.
Two technical standards help put Article 50 labels into practice:
| Standard | What it does | Example values |
|---|---|---|
| IPTC metadata | Adds a machine-readable field inside the image file | DigitalSourceType: trainedAlgorithmicMedia (fully AI-generated); compositeWithTrainedAlgorithmicMedia (AI mixed with real content) |
| C2PA Content Credentials | Adds a tamper-proof record that shows how the file was made and edited | Full edit history stored in the file |
Metadata alone is not enough for people viewing the image. The European Commission has also released a set of optional icons for marking AI content, available since June 2026, as part of its Code of Practice on Transparency of AI-generated Content. Using an icon is not the same as meeting the legal duty. The icon alone does not satisfy Article 50, and the duty does not go away just because a platform removes the icon or the metadata during upload. To follow the Commission's guidance, a label should:
Non-compliance is expensive. Under Article 99(4) of Regulation (EU) 2024/1689, breaking Article 50 can lead to a fine of up to €15 million or 3% of the company's total worldwide annual turnover from the year before, whichever is higher. Smaller companies - small and medium-sized enterprises (SMEs) - have a lower limit. Article 99(4) also covers several other rules (Articles 16, 22, 23, 24, 26, 31, 33, and 34) under this same fine level.
This is a lower fine level than the €35 million or 7% limit under Article 99(3), which is only for the banned, prohibited practices under the unacceptable-risk tier. There is a third, even lower level under Article 99(5): up to €7.5 million or 1% of turnover, for giving false or misleading information to regulators. Several bodies can enforce these rules together: national market authorities, the EU's AI Office, and the European Data Protection Supervisor. High-risk AI systems carry their own extra duties, like human oversight and reporting serious incidents, which sit outside this Article 50 penalty structure. Regulators have said they will consider how well a company documented its compliance efforts when deciding on a fine, and legal interpretation of these factors is still developing in practice.
No. Article 50 does not ban AI-generated or AI-edited product images. It just says you must disclose when an image is artificially generated or changed, if it could otherwise look completely real.
No. Color correction, cropping, background cleanup, and other normal retouching on a real, photographed product are exempt from Article 50.
On August 2, 2026, along with most of the rest of Regulation (EU) 2024/1689. There is no general grace period for this rule. A separate transition period, running until December 2, 2026, only covers a provider's technical marking of AI systems already on the market before that date - not the disclosure duty itself. (source)
Yes. Article 50 applies to any business that shows images to people in the EU, no matter where that business is based.
Yes. Getting someone's consent to use their face, voice, or image is a separate matter from disclosure. It's about rights and permission, not about transparency. If the content still meets Article 50's disclosure rules, you must still label it, even with consent.
Up to €15 million or 3% of global yearly turnover, whichever is higher, with a lower limit for smaller companies, under Article 99(4) of Regulation (EU) 2024/1689.
This article reflects the EU AI Act's transparency rules as they stood in August 2026, including changes made by Regulation (EU) 2026/1744. Guidance in this area is still changing. Talk to a qualified lawyer before you finalize a company-wide labeling policy.
November 3, 2020
A complete guide to 360 degree product photography. Get info and tips on 360 spin product photography, 360 product photography equipment, and software.
April 24, 2024
The equipment, light types, and positions behind a working product photography lighting setup - plus how to build one step by step, whether you shoot with a single lamp or automate a full e-commerce catalog.
August 19, 2026
An automated dimensioning system captures length, width, height, and weight in one pass. Here is why warehouse teams still capture product data three times, and what one-pass capture changes.