On 2 August 2026 the transparency rules in Article 50 of the EU AI Act became enforceable. Most of the coverage was about chatbots having to admit they are chatbots. The part that reaches marketing teams is quieter: an AI-generated image of your own product, used in an ad, can count as a deepfake.
Not because it impersonates anyone. Because it looks real and is not.
The definition is wider than the word suggests
In American usage, deepfake means face-swapping or voice cloning. The AI Act means something broader. Article 3(60) defines it as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic.
Objects. Places. Events. The test is not whether you replicated a real person. It is whether a viewer would take the content for an authentic depiction of something real, when it is synthetic.
The European Commission’s final guidelines came with examples, and advertising lawyers at Davis+Gilbert pulled out the ones that matter in their briefing on AI disclosure rules for advertisers.
Counts as a deepfake: an AI-generated product image in an ad or on packaging that could mislead about the product’s actual appearance, characteristics or use, including making it look more appealing or higher quality than it really is. An AI-generated video of a celebrity influencer in a promotional context. A synthetic influencer demonstrating a real product.
Does not count: an AI-generated video of mice arguing about cheese in a cheese ad. A real car shot against an AI-generated background, as long as the ad does not mislead about the car. Audio cleanup that leaves the spoken words untouched. An AI cartoon version of a historical photograph.
The dividing line is deceptive realism. Obviously fantastical content sits outside it. Routine post-production such as colour correction, noise reduction or lighting adjustment generally triggers nothing. De-aging a performer or simulating part of a performance does.
Being outside the EU does not help
This is what US and UK businesses are getting wrong. The Act reaches organisations by where their output lands, not by where they are incorporated. The Commission’s guidelines note directly that a non-EU advertiser using AI to generate a deepfake for an ad displayed in the EU can be treated as a deployer.
In practice that catches:
- Programmatic, video or social campaigns that serve to EU users, including ones where EU delivery was never the plan
- Social ads on any platform with EU users, where the campaign is available to them
- Ecommerce sites and landing pages carrying AI-generated product imagery that EU customers can reach
A five-person Shopify brand in Ohio that generated its lifestyle shots in an AI tool, ships to Ireland, and runs Meta ads without geo-exclusions is inside the scope. No European entity, no European staff, and no obvious reason to have read any of this.
Text has an exit. Images do not.
Article 50(4) also covers AI-generated text published to inform the public on matters of public interest. In marketing that can reach product claims or PR touching health, safety, environmental, financial or scientific questions. Corporate reports and investor communications sit in the same bucket.
Text has a carve-out that imagery lacks. No disclosure is required where the content went through meaningful human review and editorial control, and a named person or entity takes responsibility for it. The guidance is explicit that this has to be substantive rather than a cursory approval click.
So a blog post drafted with AI and genuinely edited by someone who owns the output does not need a label. A product photograph generated by AI does, no matter how carefully a human reviewed it. Editorial review answers a question about authorship. It does not make a synthetic image real.
There is also a creative and artistic carve-out with lighter disclosure requirements. Do not plan around it. The guidance says that where content mixes commercial and creative characteristics, the commercial character generally prevails, so advertising rarely qualifies.
What “disclosed” has to look like
Disclosure must be clear and distinguishable, delivered at the latest on first exposure, and consistent with accessibility requirements. The Future of Life Institute’s practical guide to Article 50 is blunt about what fails: small text in a website footer, a faint label on an image, a label that flashes on a video for an instant, anything buried in terms and conditions.
A Code of Practice is developing a standardised EU “AI” label, localised per language, plus a split between fully AI-generated and AI-assisted content. It is voluntary, but it will likely become the benchmark regulators measure against.
Platforms are moving in parallel, which helps a little. Google now applies visible AI overlays to ads targeting the EU, so some of your paid creative may end up labelled whether or not you set anything. That covers ads running through Google. It does nothing for your own website, your marketplace listings or your packaging.
One timing detail worth knowing. Providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement, under the AI Omnibus provisional agreement from May 2026. That is a provider deadline, not a deployer one. And deployers cannot discharge their own disclosure duty by pointing at the provider’s machine-readable mark. Invisible metadata is not a disclosure to a human being.
What to do, and where this gets uncertain
- Inventory your published AI imagery: website, ads, packaging, marketplace listings. Most teams have never made this list.
- Sort it by realism, not by which tool made it. A photorealistic generated product shot is the problem. A stylised illustration usually is not.
- Fix product shots first. Imagery that misrepresents the actual product carries consumer-protection exposure regardless of the AI Act.
- Write down your editorial review process for AI-assisted text, and name who holds responsibility. Without a named person, the carve-out is hard to lean on.
- Content published before 2 August 2026 does not need retroactive labelling. Do not spend the weekend relabelling your archive.
Now the honest caveats. Enforcement practice does not exist yet. Nobody knows how hard national authorities will pursue a small foreign advertiser compared with a large platform, and the realistic first wave targets scale. Penalties reach 15 million euros or 3% of worldwide annual turnover, whichever is higher, but a fine of that shape is not what a ten-person company should be planning around. The proportionate response is an inventory and a labelling habit, not a compliance programme.
This may not be worth your time at all if you sell only domestically, geo-exclude the EU properly, and use no photorealistic generated imagery. Check the second of those before assuming it.
The reframe worth keeping: stop asking whether you used AI. Ask whether a reasonable viewer would think your picture is a photograph. That question has a clearer answer, and it is the one the regulation is actually built around.
Editor’s note: This area changes quickly, so check the latest platform policy before making compliance decisions.
