The EU AI Act hits your store on 2 August 2026: what you actually have to mark, and what you don't
Article 50 applies from 2 August 2026. Most of the advice you will read says label every AI image, which is wrong and will cost you. Here is what the law and the Commission's own guidelines actually say, platform by platform, with the UK position.
Ten days from now, a shopper in Dublin or Düsseldorf can open your product page, read a chat reply they think came from a person, look at an image they think is a photograph, and be wrong about both. From 2 August 2026 that's a regulatory problem with a number attached: up to 15 million euro, or 3% of worldwide turnover, whichever is higher[14].
That's the headline every other article is running. Here's the part they're getting wrong.
Almost everything published on Article 50 in the last month tells merchants to label all their AI-generated images. That advice is wrong. Not "overly cautious". Wrong. The obligation that lands on you as a shop owner is narrower, it targets a specific kind of deception, and the Commission published 51 pages of guidelines on 20 July spelling out exactly where the line sits[5]. Three days ago. Most of what you're reading predates it.
I'll be straight about my own record. For most of this year I told merchants their job was to get C2PA content credentials embedded into every AI-generated product image. Wrong duty, wrong party. I was reading the wrong paragraph.
This is not legal advice. It's an operator's reading of primary sources, every one of them linked. If you're making a decision with money attached, get a lawyer to look at your specific setup.
What actually changes on 2 August, and what doesn't
The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages[15]. Prohibitions and the AI-literacy duty started on 2 February 2025. General-purpose AI model rules started on 2 August 2025. Chapter IV, a single article, starts on 2 August 2026[3].
Article 50 does four separate things and they land on different people. Mixing them up is the single biggest source of bad advice on this topic.
| Paragraph | Duty | Who it binds | Applies from |
|---|---|---|---|
| 50(1) | Tell people they're talking to an AI | Provider of the interactive system | 2 August 2026 |
| 50(2) | Mark outputs in a machine-readable format, and make them detectable | Provider of the generative system | 2 August 2026 (2 December 2026 for systems already on the market) |
| 50(3) | Tell people about emotion recognition or biometric categorisation | Deployer | 2 August 2026 |
| 50(4) | Visibly disclose deepfakes, and AI text published on matters of public interest | Deployer | 2 August 2026 |
Read that table again. Two of the four duties sit on whoever built the AI system, not whoever uses it. Buy an image generator or a chat assistant off the shelf, use it as-is, and you're a deployer with only paragraphs 3 and 4 to worry about[6].
What the omnibus moved, and what it didn't
The Digital Omnibus on AI, proposed on 19 November 2025, delayed a big chunk of the AI Act. Parliament approved the deal on 16 June 2026 by 423 votes to 57 with 174 abstentions, and the Council signed it off on 29 June. High-risk rules moved to 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products[17].
Article 50 did not move. The only thing the omnibus touched in Chapter IV is a transitional rule: the machine-readable marking duty in 50(2) is pushed to 2 December 2026, and only for generative systems already on the market before 2 August 2026[3]. That's a grace period for model vendors, not for you. A system that's partly interactive and partly generative gets the extension for marking only, and must still comply with the chatbot disclosure duty on 2 August[5].
One piece of good news almost nobody has picked up. Content generated before 2 August 2026 doesn't have to be labelled retroactively[6]. Two years of generated lifestyle shots in the catalogue? Leave them. The Commission encourages relabelling but says plainly it doesn't expect you to audit pre-existing content databases or reprint packaging[5]. One catch: text generated before the date but published on or after it does need labelling, where the text rule applies at all.
Does this actually impact you?
Probably. Article 2 catches providers placing AI systems on the Union market wherever they're established, deployers established in the Union, and providers and deployers in a third country "where the output produced by the AI system is used in the Union"[16].
A Manchester store shipping to France is in scope. So is a Brooklyn store shipping to Ireland. The guidelines pin the test for third-country deployers to foreseeability: obligations bite where the deployer itself foresees the output being used in the Union, including by posting it on the openly accessible internet, and don't bite where content reaches EU audiences through channels that are unforeseeable and outside your control[5]. Take EU orders, ship EU parcels, and you don't get to argue you didn't foresee it.
You're a deployer, which is better news than it sounds
A "provider" develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A "deployer" uses an AI system under its authority in a professional capacity[11].
Buy Shopify Magic, Adobe Firefly, Midjourney, an off-the-shelf support assistant. Use it. You're a deployer. Your employees aren't separate deployers, and the company stays the deployer even where contractors and freelancers do the work on its behalf[6].
Useful carve-out for anyone who outsources creative. A company that "merely commissions an advertising agency to produce an advertisement, without taking decisions and exercising control over whether and how the advertising agency uses AI in the production process, is not a deployer"[5]. If your agency picks the tools and you never see the pipeline, the duty follows the agency. Put a clause in the next contract either way.
When a merchant becomes a provider
Build a chat assistant in-house and put it into service under your own brand, and the guidelines name you a provider directly[5]. Fine-tune an existing model with your catalogue and ship it under your own name, and you're the provider of that new system, without letting the original provider off the hook for theirs. Build a generator in-house and use it yourself, and you're both at once, carrying the marking duty and the labelling duty together[5].
A lot of "we built our own AI concierge on the OpenAI API" stories are provider stories. If that's you, paragraphs 1 and 2 are yours now, and paragraph 2 is the expensive one.
The stakes if you do nothing
Article 99(4)(g) puts breaches of Article 50 in the middle band: up to 15,000,000 euro or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups the fine is capped at whichever is lower[14], which for a small business means the percentage, not the eight-figure number. That distinction is missing from about nine out of ten pieces I've read this month, and it changes the risk picture completely for a £2m store.
Enforcement runs through national market surveillance authorities, with the AI Office competent only in narrow cases[4]. They can act on their own initiative or on a complaint, and Article 85 gives any affected person the right to complain[5]. So the realistic trigger isn't a day-one market sweep. It's one annoyed customer, one competitor, or one consumer group with a form.
The quieter risk will bite first. Article 50 sits alongside the Unfair Commercial Practices Directive, and the guidelines say so: misleading actions or omissions about the main characteristics of a product stay prohibited under Directive 2005/29/EC whatever the AI Act says[5]. An AI-enhanced product shot that flatters the item was already a consumer-law problem before anyone drafted Article 50. In the UK that's section 226 of the Digital Markets, Competition and Consumers Act 2024[40], which has teeth and doesn't need an AI Act to use them.
What we found: the marking chain is already broken on Shopify
Here's the bit I couldn't find anywhere else, so we checked it ourselves.
On 23 July 2026 we pulled 60 live product images from six UK Shopify stores using each store's public products.json endpoint, so the URLs are the real ones a shopper's browser loads. Gymshark, TALA, Lucy & Yak, Passenger, Finisterre and Snag. Every image served from cdn.shopify.com. Then we scanned the raw bytes for four things: an XMP packet, a C2PA manifest, an IPTC DigitalSourceType field, and an EXIF block.
| Marker | What it carries | Found in |
|---|---|---|
| EXIF block | Camera and capture data | 54 of 60 |
| XMP packet | Where IPTC and provenance assertions live | 0 of 60 |
| C2PA manifest | Signed content credentials | 0 of 60 |
| IPTC DigitalSourceType | The AI-origin flag itself | 0 of 60 |
Method notes, because they matter. We can't prove any of those 60 images were AI-generated, so zero AI flags isn't itself the finding. The row above it is. EXIF survived on 90% of files, so the pipeline plainly isn't stripping everything. Not one file carried an XMP packet, and XMP is precisely where the IPTC DigitalSourceType value and C2PA-style provenance assertions get written[24]. We sanity-checked the detector against Wikimedia originals first. It reads metadata fine.
Shopify has known since May
That lines up with a report on Shopify's own developer forum. A developer showed an AI-generated image carrying the TrainedAlgorithmicMedia IPTC tag losing it once hosted on Shopify's CDN. On 14 May 2026 a Shopify staff member replied: "We are looking in to this. I don't have a timeline on a resolution, but we will update here with any updates." On 9 July 2026 another developer reported it still happening across every upload method, and flagged the 2 August deadline[30]. No fix in the thread.
This isn't only an AI Act question. Google Merchant Center already tells merchants not to remove embedded metadata tags such as the IPTC DigitalSourceType property from images created with generative AI, across image_link, additional_image_link and lifestyle_image_link[28]. If your CDN strips it, you can satisfy Google's rule perfectly at upload and still fail it at serve.
So if you're relying on invisible metadata to meet your obligation, you've built on sand. You shouldn't have been relying on it anyway, because it isn't your obligation.
Everyone is about to over-label, and that's the wrong move
Here's the claim I'll defend. Labelling every AI-touched image isn't "playing it safe". It misstates the obligation and devalues the labels that carry real information.
The deployer duty in 50(4) isn't about tooling. It's about deception. It applies to deepfakes, and "deep fake" is a defined term in Article 3(60): "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful"[11].
The three tests content has to pass before you label it
The Commission's Q&A breaks that into three cumulative criteria. All three have to be met[6].
- Resemblance. A high level of similarity between the content and the thing it simulates.
- Existing. The simulated person, object, place, entity or event has to resemble something that exists, could plausibly exist, or could plausibly have existed.
- False appearance of being authentic or truthful. It has to be capable of misleading someone about its authenticity or truthfulness.
The assessment is objective, so you don't have to intend to deceive anyone for content to qualify. It's also contextual: you weigh the resemblance, the substantive message, the deployment context, and the audience you can reasonably foresee[6]. High photorealism makes deepfake status more likely, "but photorealism alone is not determinative"[5].
The Commission's own examples, mapped onto a product page
Bookmark this table. The guidelines give worked examples and several are commercial. I've mapped them onto ecommerce assets.
| Asset | Label it? | Why, in the Commission's words |
|---|---|---|
| Fully AI-generated image of your product that makes it look "not identical to the real product, more appealing or with improved quality than in real life" | Yes | Listed as an example of a deepfake[5] |
| Your real product shot placed against an AI-generated background or environment | No, provided the ad isn't likely to mislead about the product's actual representation, characteristics or use | Listed as an example that does not constitute a deepfake[5] |
| AI colour correction, background extension or replacement for aesthetic purposes, rearranging existing products, rescaling | No | "Likely to have only a minor impact on a person's perception of the authenticity and truthfulness of the advertisement and the product"[5] |
| A synthetic avatar of your founder or CEO in a brand video | Yes | Listed example[5] |
| An AI-generated depiction of a celebrity or influencer in a promotional context | Yes | Listed example[5] |
| Teleshopping-style video with simulated humans demonstrating the product | Yes | Listed example[5] |
| A chart, a schematic, an infographic, a designed diagram | No | Fails the "existing" and "false appearance" tests. Usually not an AI output at all |
| An obviously fantastical image (the guidelines use a sphinx over the Eiffel Tower) | No | Listed as not a deepfake[5] |
Notice what the test asks. Not "did a machine touch the pixels". It asks whether a person did the creative work, or whether a prompt produced something a reader would take for a record of the real world. The car-against-a-generated-backdrop example is the clearest statement of it. Real product, synthetic scenery, no label, because nothing about the product itself is misrepresented.
The EU's icon guidance gives another useful analogue: an authentic photograph of an empty apartment furnished using AI is a "Partially AI-Modified" case that needs a label[10]. That's your dividing line for room-set and lifestyle imagery. Change the room, you're fine. Change what the shopper believes about the goods in it, you're not.
Why over-marking is a real cost, not a free hedge
An "AI" badge on everything tells the shopper nothing, so when it appears on something that genuinely could mislead them, they'll skate straight past it. The point of the regime, as the Commission puts it, is to help people "calibrate their trust"[4]. A label that's always on is a label nobody reads. The Code sets real placement rules too, so a badge in the top-right of every product image is a conversion cost you're paying for nothing[8]. And badging a hand-shot photograph as AI-generated tells your customer something untrue, on a page where truthfulness is regulated.
You could reasonably disagree with me. The counter-argument is that the deepfake test is fuzzy at the edges, the fines are large, and blanket labelling is cheap insurance. I think that's wrong on the economics and wrong on the law. But a sensible person can make it. What isn't defensible is doing it without knowing which of the two you've chosen.
The chatbot rule is the one most stores will actually breach
If you take one operational thing from this piece, take this. Article 50(1) requires AI systems intended to interact directly with people to be designed so those people are informed they're interacting with an AI, unless it's obvious to a reasonably well-informed, observant and circumspect person[1]. The Commission's list of in-scope systems names "chatbots/conversational agents in various contexts (e.g. public service, customer support, complaints management, e-commerce, finance, healthcare, education)"[5]. Ecommerce, by name.
"It's obvious it's a bot" is not a defence
The exception has to be read restrictively, "given that it deprives natural persons from the protection and the right to be informed". General awareness that chatbots exist doesn't mean people recognise them in an actual interaction, and the exception is limited to cases "where there is almost no doubt left about the nature of the interaction"[5].
Then this, verbatim, from the list of cases that fail the obviousness exception: "AI chatbots embedded in online platforms or assistance support tools (helpdesks) whereby users directly interact and receive AI outputs (e.g. replies to queries or other AI-generated content) they may perceive as human-generated"[5]. That's your support widget. Written down, by the Commission, as an example of the thing that needs a disclosure.
Some relief on scope. These are explicitly outside 50(1): recommender systems, spam filters, automated translation, search and retrieval that doesn't generate or modify content, text and code autocomplete, and "AI-assisted product visualisation (e.g., virtual try-on, room staging, product rendering)"[5]. Your recommendations carousel doesn't need a banner. Neither does your AI site search, as long as it retrieves rather than writes.
A human in the loop only helps if the human is genuinely the interlocutor. Products mixing AI replies with human-curated content need disclosure for the AI parts, "unless those AI outputs have been properly reviewed and sent by humans as the main interlocutors"[5]. Suggested replies your agents read and send: outside. Auto-send with a review button nobody clicks: inside.
AI agents have to say who they work for
AI agents are covered by 50(1) where they interact with the person instructing them or with anyone else while executing a task, and the guidelines give shopping examples: making bookings, negotiating or concluding contracts, executing purchases. Agents "must be designed and developed in such a way that they disclose both their artificial nature and the person on whose behalf they are acting"[5].
Two-sided. Build a buying agent and it has to identify itself and its principal. Receive agent traffic as a merchant and the law now expects the agent on the other end to tell you what it is, which is a firmer foundation for agent policy than anything in the current protocol specs. Read it alongside where AI in ecommerce actually stands in 2026.
What machine-readable marking requires, and why it isn't your job
Article 50(2) is the paragraph everyone quotes and almost nobody reads to the end. Providers of systems generating synthetic audio, image, video or text must ensure outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated"[1].
Providers. Not deployers. Use Firefly or Magic or Midjourney and the duty to mark sits with whoever built the generator.
C2PA is a technique, not the law
Here's the correction to my earlier advice. Neither the Commission's guidelines nor the Code of Practice names C2PA anywhere. I read both end to end looking for it. Recital 133 lists the acceptable approaches: "watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques"[13]. C2PA is one credible way to do the cryptographic-provenance part[22], and its own Interim Trust List was frozen on 1 January 2026 in favour of a formal conformance programme[23]. It isn't a legal requirement, and on its own it isn't sufficient under the Code either. The guidelines also release providers from the thing most people assume C2PA obliges: they "are not required to record or keep a full provenance chain containing information on content origin and modifications"[5]. Marking isn't provenance.
What the Code of Practice actually asks for
The final Code was published on 10 June 2026[9] and it's voluntary[7]. Signing is the only Union-wide recognised way to demonstrate compliance with 50(2), (4) and (5). Non-signatories have to show adequacy by other means, run a gap analysis against the Code, and expect more requests for information[5].
For providers, Measure 1.1 requires at least two layers of machine-readable marking while no single technique satisfies all four statutory requirements: digitally signed, time-stamped metadata where the format supports it, plus an imperceptible watermark[8]. Free-form text can't carry metadata, so one layer is accepted there. Google's SynthID is the best-known watermark example[27], vendor-published, so read it as illustration rather than benchmark.
For deployers, Section 2 sets the visible label. Main element: the capitalised acronym "AI", optionally supplemented with "generated" or "modified" and a second layer explaining what changed. Placement: perceivable without user action, no intervening overlays, top-right of an image or video, embedded in the content unless an equivalent UI overlay is available, repeated through video at intervals and after ad breaks[8]. The EU publishes the icon set free, no attribution required[10].
And the most important sentence for merchants in the whole document: deployers "cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2) AI Act, since those markings are not immediately clear and distinguishable"[5]. So the metadata-stripping problem, real as it is, isn't your compliance failure. Your obligation was always the visible label.
If you're on Shopify
Shopify Magic's media generation applies an invisible watermark to all generated images, described in Shopify's own documentation as "a form of 'metadata' on content that's generated with AI", undetectable to the eye and not removable. It's on Basic through Plus at no extra cost[31]. So Shopify is doing provider-side work on 50(2)[32], which is the right division of labour.
What Shopify doesn't ship is a deployer-side control. No field on a product image saying "this is AI-generated", no theme setting that renders the EU icon, nowhere to record the decision. That's the gap, and it's the same gap on every platform here.
Practically, on Shopify:
- Add a metafield on
Productor onMediaImage: a boolean plus a short reason string. Namespace it something likecompliance.ai_disclosure. - Render the EU icon in your gallery snippet when the flag is true. Top-right, outside any zoom overlay, and check it survives the lightbox and the mobile carousel.
- Put an
altoraria-labelon the badge saying the content is AI-generated. The Code asks for assistive-technology detectability[8]. - Shopify Inbox, Sidekick-powered chat or any third-party assistant: the AI disclosure has to appear at or before the first message. Not in a tooltip, not in the terms.
- Don't burn engineering time forcing IPTC tags through the CDN until Shopify fixes the stripping[30]. It isn't your duty and it currently doesn't work.
Not on Shopify? WooCommerce, Adobe Commerce and BigCommerce
All three ship AI features. None has a disclosure primitive. Same job, three different amounts of work. If you're weighing a move between them, the platform comparison is the wider argument.
WooCommerce
WooCommerce AI is a conversational admin assistant, in private beta and limited to US stores not hosted on WordPress.com[33]. It's staff-facing, so 50(1) doesn't bite: the guidelines treat an internal employee-facing assistant for trained staff as an obviousness case[5]. Your customer-facing exposure is Jetpack AI, which generates copy and images in the editor[34], plus whatever chat plugin you've installed.
Woo is the easiest to fix because you own the stack. A post meta key, a filter on woocommerce_single_product_image_thumbnail_html, a template override. An afternoon. Put the flag on the media attachment as well as the product, so it travels with the asset.
Adobe Commerce / Magento
Adobe's position is the strongest, because Adobe co-founded the provenance work and Firefly attaches Content Credentials to generated assets by default[25]. Firefly into Adobe Commerce is the best-marked pipeline available to a merchant right now.
Two caveats. Credentials only survive if every hop preserves them, and image CDNs and resizing pipelines are where they die. And Commerce's merchandising and recommendation services[36] sit outside 50(1) as recommender systems[5]. On the deployer side you're building the same badge as everyone else, via a product attribute and a template.
BigCommerce
BigAI Copywriter generates product copy in the admin[35], and the app marketplace carries a long list of third-party AI description and image tools[43]. Generated product descriptions are almost certainly out of scope for the deployer text duty, because 50(4)'s second subparagraph only covers text "published with the purpose of informing the public on matters of public interest"[1], and the guidelines list AI-manipulated text forming part of a company's advertisement or product descriptions as an example falling outside it[5].
Worth saying plainly: you do not have to label AI-written product descriptions. Your blog post on a public-health topic might be a different question. Your listing copy isn't.
There is a related point that catches people out. The same product data an AI agent reads to decide whether to recommend you is the data a customer gets quoted, and a stale price or a returns window you do not honour creates a problem no disclosure label fixes. Our agentic commerce readiness checklist covers the three fields that decide it.
Custom and headless builds
Most freedom, most rope. Put the flag in your PIM or DAM rather than the storefront, so it survives a replatform and reaches every channel: web, app, marketplace feed, retail media, email. If you're integrating a model API directly and shipping it under your own brand, check whether you've become a provider, because then paragraphs 1 and 2 are yours and the Code's two-layer marking expectation applies to you[8]. Our replatforming piece makes the case for keeping compliance state out of the theme layer, and the PIM question is where the flag should probably live.
The developer checklist
Hand this to whoever builds your store. It's the whole implementation.
- Inventory every AI system touching a customer. Chat, search, recommendations, generated media, generated copy, try-on, voice. Record the vendor, whether you modified it, and whether you're deployer or provider for each.
- Add a disclosure flag to the asset, not the page. Product metafield, media attribute or PIM field. Boolean plus a free-text reason. It has to travel with the asset into feeds and apps.
- Build one badge component. Capitalised "AI", optional "generated" or "modified" text, optional second layer explaining what changed[8]. The EU icons are free and need no attribution[10].
- Place it where it can't be missed. Top-right, no intervening overlays, visible long enough to read, present in the lightbox, the mobile carousel and the reshared or downloaded file[8].
- Make it accessible. Alt text or ARIA label announcing AI origin, sufficient contrast, plain language, no abbreviation other than "AI"[10]. Article 50(5) ties this to the existing accessibility directives[1]; our accessibility piece covers those.
- Disclose the assistant on first message. Not on hover, not in the privacy policy, not "hidden under layers of menu options"[5]. A persistent badge in the chat header is the cheapest compliant pattern. The helpdesk comparison covers which vendors ship it.
- Check what your generator writes into the file. Look for an IPTC
DigitalSourceTypeoftrainedAlgorithmicMedia[24] and a C2PA manifest. The Content Authenticity Initiative's open-source tools read both[26]. - Then check what survives your CDN. Fetch the served file, not the source, and diff. Don't assume, measure.
- Preserve metadata for Google separately. Merchant Center wants those tags kept[28], and Google Search has its own guidance on AI-generated content[29]. Different rules, same file.
- Write down the decision for each borderline asset. One line: what it is, which of the three deepfake criteria it fails, who decided, when. This is the thing you'll be asked for.
- Do the AI-literacy piece. Article 4 has been in force since 2 February 2025 and requires providers and deployers to ensure a sufficient level of AI literacy among staff operating these systems[42]. Nobody talks about it. It's already law.
The full per-platform version, with the vendor questions and the records list, is in our EU AI Act compliance guide for ecommerce.
The UK angle: no AI Act, still caught
The UK has no equivalent statute. AI is regulated through whichever existing framework covers the context, the approach set out in the 2023 pro-innovation white paper and never replaced by primary legislation[39]. There's no UK requirement to label AI-generated content.
That doesn't help you if you sell into the EU. Article 2(1)(c) catches deployers located in a third country where the output is used in the Union[16], and the guidelines confirm the foreseeability test pulls in a third-country company whose AI-generated advertisement is displayed in the Union[5]. A UK store with a French storefront and euro pricing is squarely inside.
What is moving in the UK is data protection. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made on 16 April 2026 and came into force on 12 May 2026, requiring the Information Commissioner to prepare a statutory code covering development and deployment of AI systems, automated decision-making, and children's personal data[38]. The ICO's existing AI guidance is under review because of the Data (Use and Access) Act[37], and its AI and biometrics strategy sets out the plan[41].
The honest UK position: the AI labelling duty is an EU export requirement, the data-protection duties are domestic and tightening, and the misleading-advertising duties under the DMCC Act 2024 were already there[40]. Most UK stores selling across the Channel will find one implementation cheaper than two. Same conclusion we reached on the EU right of withdrawal, for the same reason: dual-regime storefronts cost more to maintain than they save. Selling into more than one market? The international piece has the rest of it.
What's still unclear, honestly
Three things I'd rather flag than pretend about.
The guidelines say of themselves that they're "a first interpretation", that the Commission will review them in light of enforcement experience and CJEU interpretation, and that it may withdraw or amend them[5]. Guidelines aren't binding law. The worked examples above are the Commission's reading, not a court's.
Nobody knows how national market surveillance authorities will behave from August. The Commission maintains the list of designated authorities[19], and capacity varies enormously between member states. Anyone telling you what the first enforcement action will look like is guessing.
The signatory position is still forming. Signing the Code is open, with a published form and instructions[21]. Which generative vendors have actually signed, and what they've opted out of, is worth checking against the Commission's list rather than taking a vendor's word. Signatories can opt out of sections, and opting out costs them the compliance presumption for that section[5].
A smaller one that tells you how fresh all this is. As of 23 July 2026 the Commission's own Q&A page attributes the chatbot-disclosure duty to Article 50(2). It's Article 50(1)[6]. Everyone is three days into these documents, including the people who wrote them. Their quick-facts page is the shortest orientation if you want one[20].
What to do this week
- Today: turn on the chat disclosure. A config change or a one-line theme edit in most setups, the duty most likely to be breached, and there's no grace period. Start of first interaction, clear and distinguishable[1].
- Tomorrow: sort your generated media into three piles. Fully generated product imagery. Real product plus generated environment. Everything else. Only the first pile is likely to need a label[5].
- This week: build the badge once. One component, one flag, driven from the asset record. Don't hard-code it into templates.
- This week: email your two loudest AI vendors. Have they signed the Code, which sections have they opted out of, what marking do they apply, and do they consider you a deployer or a provider of their system? In writing.
- Before 2 August: fetch ten of your served images and check what metadata survives. Twenty minutes with curl, and you'll learn more about your pipeline than any vendor deck will tell you.
- Before 2 August: write the one-page record. Systems, roles, decisions, dates. If someone asks in September, this is the answer.
- Diary 2 December 2026. The 50(2) transitional period ends, and the new prohibitions on non-consensual intimate imagery start the same day[3].
The takeaway
Article 50 applies on 2 August 2026 and the omnibus didn't move it[3]. Most merchants are deployers, so two of the four duties are yours: tell people about emotion recognition or biometric categorisation if you use it, and put a visible, perceivable label on deepfakes[2]. The machine-readable marking everyone is panicking about belongs to whoever built the generator[6].
And a deepfake is a specific thing. Something resembling a real person, object, place or event that would falsely appear to be authentic[12]. A generated image of your product that makes it look better than it is: label it. A real product against a generated backdrop: the Commission says no[5]. Charts, diagrams, product descriptions: no.
Anyone selling you a blanket-labelling project is selling you work the law didn't ask for, plus a worse customer experience than the one you already have. Spend that budget on the chat disclosure and the one-page record instead, because those are the two things that will actually be missing on 3 August. The rest of the statute is at the Act itself[44], and the omnibus proposal is worth a skim[18].
Open your store's chat widget now. Does the first thing it says tell the customer it's an AI?
Sources
Every URL below was checked on 23 July 2026. Links marked with an asterisk return 403 to command-line requests but were verified by page fetch. EUR-Lex blocks automated requests entirely, so the Official Journal text is cited through the Commission's own AI Act Service Desk and the Future of Life Institute's article-by-article reproduction of the OJ version of 13 June 2024.
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems. Regulation (EU) 2024/1689, OJ version of 13 June 2024, reproduced by the Future of Life Institute. Accessed 23 July 2026.
- Article 50, AI Act Explorer. European Commission AI Act Service Desk. Accessed 23 July 2026.
- Timeline for the Implementation of the EU AI Act. European Commission AI Act Service Desk, incorporating the Digital Omnibus on AI amendments. Accessed 23 July 2026.
- Guidelines on Transparency of AI-Generated Content. European Commission. Last updated 20 July 2026.
- Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689. European Commission, C(2026) 5054 final, Brussels, 20 July 2026, 51 pages. Direct PDF.
- Questions and Answers: Transparency obligations under Article 50 of the AI Act. European Commission. Last updated 20 July 2026.
- Code of Practice on Transparency of AI-Generated Content. European Commission policy page. Last updated 20 July 2026.
- Code of Practice on Transparency of AI-Generated Content (PDF, 38 pages). Drawn up by independent chairs in a multi-stakeholder process facilitated by the AI Office. Published 10 June 2026.
- Commission publishes Code of Practice on marking and labelling AI-generated content. European Commission press release, 10 June 2026.
- EU Icons for labelling AI-generated content. European Commission. Free to use, no attribution required. Accessed 23 July 2026.
- Article 3: Definitions. Regulation (EU) 2024/1689. Definitions (3) provider, (4) deployer, (60) deep fake.
- Recital 134. Regulation (EU) 2024/1689. Deepfake disclosure and the artistic-works limitation.
- Recital 133. Regulation (EU) 2024/1689. Marking techniques: watermarks, metadata, cryptographic provenance, logging, fingerprints.
- Article 99: Penalties. Regulation (EU) 2024/1689. Article 50 breaches sit in the 15,000,000 euro / 3% band at 99(4)(g); the SME cap is at 99(6).
- Article 113: Entry into Force and Application. Regulation (EU) 2024/1689.
- Article 2: Scope. Regulation (EU) 2024/1689. Extraterritorial reach at 2(1)(a) and 2(1)(c).
- Digital Omnibus on AI. European Parliament Legislative Train Schedule, Members' Research Service. Accessed 23 July 2026.
- Digital Omnibus on AI Regulation Proposal. European Commission, COM(2025) 836, 19 November 2025.
- Market surveillance authorities under the AI Act. European Commission. Accessed 23 July 2026.
- Quick Facts: Transparency rules for AI systems. European Commission fact page. Accessed 23 July 2026.
- Questions and Answers: Signing the Code of Practice on Transparency of AI-generated Content. European Commission. Accessed 23 July 2026.
- C2PA Technical Specification 2.4. Coalition for Content Provenance and Authenticity. Accessed 23 July 2026.
- C2PA Conformance Program and Trust List. The Interim Trust List was frozen on 1 January 2026. Accessed 23 July 2026.
- IPTC NewsCodes: digitalsourcetype / trainedAlgorithmicMedia. International Press Telecommunications Council. Accessed 23 July 2026.
- Content Credentials in Adobe Firefly. Content Authenticity Initiative. Adobe-led initiative, so treat as vendor-adjacent, though the underlying specification is open.
- CAI open-source tools. Free tooling to read and write Content Credentials. Accessed 23 July 2026.
- SynthID. Google DeepMind. Vendor-published; an example of the imperceptible-watermark layer the Code expects from providers.
- AI-generated content. Google Merchant Center Help. Requires preserving IPTC DigitalSourceType on AI-generated images. Accessed 23 July 2026.
- Google Search's guidance on generative AI content. Google Search Central. Accessed 23 July 2026.
- Shopify CDN stripping IPTC metadata of images. Shopify Developer Community. Shopify staff acknowledgement 14 May 2026; still reported unresolved 9 July 2026.
- Media generation in the file editor*. Shopify Help Center. "An invisible watermark is applied to all generated images." Accessed 23 July 2026.
- Shopify Magic*. Shopify Help Center. Vendor-published. Accessed 23 July 2026.
- WooCommerce AI. WooCommerce Marketplace. Private beta, US stores only at time of writing. Vendor-published. Accessed 23 July 2026.
- Jetpack AI Assistant. Automattic. Vendor-published. Accessed 23 July 2026.
- BigAI Copywriter. BigCommerce Help Center. Vendor-published. Accessed 23 July 2026.
- Product Recommendations overview. Adobe Experience League, Adobe Commerce. Vendor-published. Accessed 23 July 2026.
- Guidance on AI and data protection. Information Commissioner's Office. Last substantive update 15 March 2023; under review following the Data (Use and Access) Act.
- The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026. SI 2026/425, made 16 April 2026, in force 12 May 2026.
- A pro-innovation approach to AI regulation. UK Government white paper. Accessed 23 July 2026.
- Digital Markets, Competition and Consumers Act 2024, section 226. Misleading actions. legislation.gov.uk.
- AI and biometrics strategy: our plan of action. Information Commissioner's Office. Accessed 23 July 2026.
- Article 4: AI literacy. Regulation (EU) 2024/1689. In force since 2 February 2025.
- AI apps category. BigCommerce app marketplace. Vendor-published. Accessed 23 July 2026.
- The AI Act: full text. Regulation (EU) 2024/1689, Official Journal version of 13 June 2024, Interinstitutional File 2021/0106(COD).
Original research: on 23 July 2026 we retrieved 60 product images from six UK Shopify stores (Gymshark, TALA, Lucy & Yak, Passenger Clothing, Finisterre, Snag) via each store's public products.json endpoint, and scanned the served bytes for EXIF, XMP, C2PA and IPTC DigitalSourceType markers. Detector validated against Wikimedia Commons originals first. Small sample, one platform, publicly reproducible.