NMS - New Media Service GmbH
Der Hegau Tower in Singen, Sitz der NMS

AI images on your website: when you must label them — and when not

Article 50 of the EU AI Act has applied since 2 August 2026.

News

AI-generated

The transparency obligations of the EU AI Act have applied since 2 August 2026. Since then one question keeps reaching us: does every AI-generated image on a website now have to be labelled? The short answer is: as a rule, no.

This is the most common misconception about Article 50 — and it leads companies to spend effort the law does not require while overlooking the places where it genuinely demands something. One clarification first: what follows concerns the marking and disclosure duties under Article 50. Whether an image may be used at all is also governed by other law — there is a separate section on that below.

What has applied since 2 August 2026?

Article 50 of the AI Act became applicable on that date. It governs four situations in which people must be able to tell that artificial intelligence is involved — regardless of whether the system counts as high-risk.

  • Direct interaction with people, such as a chatbot
  • Synthetically generated or manipulated image, audio, video and text content
  • Emotion recognition and biometric categorisation
  • Deepfakes and AI-generated text published to inform the public on matters of public interest

We have compiled the wider framework — risk classes, deadlines and deployer duties — on our page about the EU AI Act for companies; the short version is in the glossary under AI Regulation.

Provider or deployer — who carries the duty?

This distinction decides everything. Providers must mark generated content in a machine-readable format so that synthetic material can be detected technically — that is paragraph 2 of the article. Deployers must disclose to people, but only in the cases covered by paragraphs 1, 3 and 4.

Anyone using an image model such as Midjourney, DALL·E or Flux in ordinary business operations is, as a rule, a deployer, and the machine-readable marking is the provider’s responsibility. The role can shift, though: putting a system on the market under your own name, or substantially modifying it, makes you a provider. And the marking should not be taken on trust — whether it is actually applied, and whether it survives export and further editing, is a question for the service you use.

Do I have to label an AI stock image?

Under Article 50, as a rule no. The deployer’s disclosure duty attaches to deepfakes — and a generic illustrative image is not one. An invented office, an abstract illustration, a scene with people who do not exist: none of these meet the criteria the regulation attaches the duty to.

There is also an exemption to the marking obligation in paragraph 2: it does not apply where the AI performs an assistive function for standard editing and does not substantially alter the input data. Denoising or brightening a photograph falls under it. Where editing shifts what the image shows, the exemption ends.

What counts as a deepfake under the regulation?

The regulation defines it in Article 3(60): generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Two elements must come together.

  • Reference to something existing: the content reproduces a real person, place, entity or event
  • False authenticity: the content would falsely appear to be authentic or truthful

An AI image convincingly reproducing a competitor’s premises meets both. An AI image of an invented person at an invented desk does not — as long as it is not presented as a photograph of real staff or real rooms. The difference lies not in how it was made, but in whether someone would be entitled to mistake it for a record of reality.

So when do you have to label after all?

Three cases actually occur in companies, and none of them involve stock imagery.

  • A chatbot on your website: users must be able to recognise that they are talking to a machine, unless it is obvious anyway
  • An AI image, video or audio clip that convincingly reproduces real people, places or events
  • AI-generated texts published to inform the public on matters of public interest — the duty falls away where the text has been reviewed by a human and a person or organisation holds editorial responsibility

For artistic, satirical or evidently fictional works the duty remains but must not hamper the display. How and when the note appears depends on the medium — what is required is that it be clear, distinguishable and timely.

Careful: no duty does not mean anything goes

This is where most guides stop — and where it can get expensive. Article 50 is not the only rule governing images on a company website. An image that carries no labelling duty can still be unlawful.

  • AI-generated faces presented as real staff, customers or references can be misleading under unfair competition law and thus actionable
  • An invented image of rooms, machines or results that do not exist advertises a quality the company does not have
  • Where real people are recognisable, personality and image rights apply regardless of how the picture was made

The rule of thumb this yields is simpler than the legal framework: an AI image may decorate, but it must not assert. The moment it makes a statement about your company — this is what our people look like, this is our workshop, these are our customers — it is the wrong image.

What still has time until December 2026?

For AI systems placed on the market before 2 August 2026, the transition period for machine-readable marking runs until 2 December 2026. It concerns only that one obligation under paragraph 2, and only providers.

Equally reassuring: content generated and published before 2 August 2026 does not need to be labelled retroactively. Nobody has to rework their image archive.

Then why do we label anyway?

Because we consider it right, and because the legal minimum is not the only standard. The images on this website that come from an image model carry a visible "AI-generated" note — including where Article 50 does not require it of us. The picture above this article included.

The reason is simple: anyone accompanying companies in responsible AI use should not work the edges of the rules themselves. Transparency costs us a line beside the image and spares every visitor the question of what is real here.

What should you do now?

For most companies, less than they fear — but more than nothing. These four steps clarify the situation in reasonable time.

  • Review your inventory: where does AI generate or alter content that goes outside the company?
  • Check chatbots and voice assistants — disclosure almost always applies here
  • Review your image practice, guided by whether a picture asserts anything about the company
  • Ensure AI literacy: since 2 February 2025, Article 4 requires appropriate measures for everyone who operates or uses AI systems

The last point is the most frequently overlooked and the longest overdue. It does not demand a certificate for every person in the building, but it does demand a risk-appropriate approach for those who actually work with the systems. We support both AI governance in Microsoft 365 and training and workshops for staff and management. If you have questions about your own situation, talk to us.

Status: August 2026. Based on Regulation (EU) 2024/1689, in particular Article 50 and Article 3(60). This article presents the legal position in simplified form, is general information and does not replace individual legal advice.