Updated September 2026. Reading time: about 6 minutes. General information, not legal advice.
Ask ten fashion teams what the EU AI Act requires for AI-generated images and most will give a version of the same answer: the images have to be marked. It is true, and it is also the beginning of the most expensive misunderstanding in this whole topic. Because the law does not require one disclosure. It requires two, they are completely different things, and they belong to different companies.
Getting this split right is the foundation for everything else in our Article 50 series. Getting it wrong usually means one party believes the other has it covered, and an image ends up published with neither duty properly met.

Disclosure one: marks for machines
Article 50(2) requires the outputs of generative AI systems to be marked in a machine-readable format. The key word is machine-readable: these marks are invisible to people and made for software. In practice, under the Code of Practice, this means two layers working together.
- Signed provenance metadata: a signed, timestamped record embedded in the file. It states that the content is AI-generated, who vouches for that statement, and when it was made, and it reveals tampering. The dominant standard is C2PA, also called Content Credentials. We explain how it works in a dedicated piece.
- An invisible watermark: an imperceptible signal woven into the pixels themselves. It carries less information than the metadata but survives what the metadata does not: re-encoding, format changes, most everyday transformations.
This duty belongs to the provider: the company that develops or offers the AI system under its own name. If a platform generates the image, the platform must ensure the marks are there.
Disclosure two: labels for people
Article 50(4) works on the opposite principle. When AI content qualifies as a deepfake, the organisation that publishes it must disclose that clearly and visibly, to humans. Not in the file's metadata. On the image, where a person scrolling past can see it.
The word deepfake carries baggage, but the legal category is wide and unemotional: content that resembles a real or plausible person, object or event, and could be mistaken for authentic. In fashion, that includes a photorealistic synthetic model wearing a garment and virtual try-on applied to a photo of a real person. The European Commission publishes free official icons for exactly this purpose: three versions, no attribution required, designed to be legible against any background.
This duty belongs to the deployer: the brand, retailer or agency publishing the image under its own authority. It has applied since 2 August 2026, with no transition window.
The split, side by side
| Machine-readable marks | Visible labels | |
|---|---|---|
| Legal basis | Article 50(2) | Article 50(4) |
| Made for | Software: verifiers, platforms, authorities | People: anyone viewing the image |
| What it is | Signed metadata plus an invisible watermark inside the file | A visible indication on the image, such as the official EU icons |
| Whose duty | The provider (the AI platform or tool) | The deployer (the brand or publisher) |
| Applies to | All AI-generated outputs | Deepfake-class content, which includes much commercial fashion imagery |
| Since when | 2 August 2026, with a narrow transition window for some existing systems until 2 December 2026 | 2 August 2026, no transition window |
Why neither replaces the other
This is the point the European Commission has made explicitly, because so many companies assumed otherwise: a deployer cannot rely on the provider's machine-readable marking to satisfy its own labelling duty. The invisible marks in the file do not discharge the visible-label obligation, and a visible icon on the image does not discharge the machine-readable one. They are separate duties, held by separate parties, serving separate audiences.
The practical consequence for fashion: one synthetic campaign image that qualifies as a deepfake legally carries both. The invisible layers travel inside the file from the platform that generated it. The visible label sits on top, placed by the brand that publishes it. If either is missing, one of the two parties has a gap.
The four mistakes we see most
- 1. A brand assumes its AI platform "handles compliance," publishes a synthetic model without a label, and holds only half a solution. The platform's marks were never able to cover the brand's duty.
- 2. A caption line like "image created with AI" buried under the fold. The label must be clear, distinguishable and visible at first interaction. A hidden caption is a weak position; the official icons exist to make the safe option free.
- 3. The reverse assumption: a publisher adds a visible label and believes the file no longer needs machine-readable marks. The provider duty does not disappear because a human can see the disclosure.
- 4. Relying on the business-to-business exemption. It requires that outputs never reach the public. Commercial imagery exists to be published, so the exemption fails for fashion by design.
What to do with this
- 1. If you publish AI imagery: classify it. Anything deepfake-class needs a visible label from you, today, regardless of what your platform does inside the file.
- 2. If you buy AI imagery: ask your platform or vendor which machine-readable marks their exports carry, and how anyone can verify them. If the answer is vague, that is your gap.
- 3. Assign each duty a name in your organisation. The split in the law works only when the split in responsibility is equally explicit internally.
The full picture, including which image operations trigger which duty and the complete classification tables, is in our Article 50 guide.




