Guide · Article 50(2) & 50(4) · AI product content

AI product descriptions and images: whose duty is the marking?

Two rules, two addressees. Article 50(2) puts the machine-readable marking duty on the provider of the generative tool. Your shop, as the deployer, answers mostly to Article 50(4), and to the quiet failure mode nobody budgets for: your own publishing pipeline stripping the provenance the tool embedded.

Article 50(2): the provider's duty

Providers of AI systems that generate synthetic image, audio, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated, as far as technically feasible. That is the tool maker, not the shop that clicks "generate". The marking lives in the file: C2PA Content Credentials, or IPTC metadata with digitalSourceType set to trainedAlgorithmicMedia. A visible caption is not machine-readable marking. The transition for systems already on the market ends 2 December 2026.

What your shop actually owes

  1. Don't strip the marking. Generators increasingly embed provenance; resizing, compression and CMS uploads routinely remove it. A file that left the model compliant reaches your visitors naked. Check one test upload. That single check is most of the work.
  2. Article 50(4) is yours. Publish an AI-generated deep fake (content resembling real persons, objects, places or events that would falsely appear authentic), and you must disclose it. Publish AI-generated text to inform the public on matters of public interest, and you must disclose that too, unless a named person takes editorial responsibility.

Are product photos deep fakes?

Usually not. Article 3(60)'s definition targets content that could be mistaken for a true record of something that exists. An illustrative render of a jacket on a model who does not exist is illustration, not a false record. Two firm caveats: an AI image of a real, identifiable person (a model, influencer, customer) presented as authentic is a deep fake. Disclose it. And the boundary is interpretation, not settled text, so photorealistic depictions of real products or places deserve a deliberate call, recorded in writing.

When a shop stops being "just" a deployer

Use a tool under your own authority (copy generator, image feature, platform AI), and you are a deployer. You would only take on provider duties by putting an AI system on the market under your own name or brand (white-labelling and reselling a tool, for instance). For a shop generating its own product content, that is rare.

Practical steps

  1. Prefer tools that mark output; keep the setting on.
  2. Stop your CMS/CDN stripping XMP/IPTC/C2PA. Verify with one test upload.
  3. Mark files you publish anyway: our free labelling tool writes IPTC digitalSourceType provenance into PNGs/JPEGs in your browser. Nothing uploads.
  4. AI images of real people presented as authentic: disclose, always.
  5. Put it in writing. A one-page labelling policy plus supplier terms that forbid removing provenance. Both ship pre-filled in the €49 Compliance Pack, with the dated evidence log.

Related

The 2 December 2026 marking deadline · Chatbot disclosure under 50(1) · Fines & enforcement · Our own transparency notice