AI-Generated Images and Deepfakes: EU AI Act Labeling Requirements
Using Midjourney for hero images, DALL-E for blog illustrations, or AI video tools for promotional content? From 2 August 2026, Article 50 of the EU AI Act requires you to label this content — and in many cases, to embed machine-readable metadata declaring its AI origin. A visible caption alone is not always enough.
This article explains what the law requires for synthetic media, which tools are affected, how deepfake-specific rules add an additional layer of obligation, and what practical steps you need to take to label AI images and video correctly on your website.
What Article 50(2) Requires for Synthetic Media
Article 50(2) imposes disclosure obligations on providers of AI systems that generate or manipulate image, audio, or video content that appreciably resembles existing persons, objects, places, or other entities or events, and that could falsely appear to a person to be authentic or truthful. Deployers (website owners) inherit a practical obligation because the tools they use should implement this — and Art. 50(4) adds a direct deployer obligation specifically for deepfakes depicting real, identifiable people (covered below).
The scope is deliberately broad. It is not limited to deepfakes of named individuals. A realistic-looking AI-generated photograph of a café interior, a product lifestyle shot that does not exist, or a video advertisement featuring synthetic presenters all fall within the definition of content that could appear authentic to a reasonable viewer.
The obligation is dual-layered:
- Visible disclosure — the content must be labeled in a manner perceptible to the person viewing or listening to it
- Machine-readable disclosure — a technical marker embedded in the content or its metadata that declares AI origin in a format that automated systems can read and verify
Both requirements apply to synthetic media published publicly — on websites, in emails, in social media posts, in advertising. If you are publishing AI-generated visuals to EU audiences, both layers are required.
The C2PA Standard: How Machine-Readable Works in Practice
The most widely adopted technical framework for machine-readable content provenance is the C2PA standard — developed by the Coalition for Content Provenance and Authenticity, a cross-industry group including Adobe, Microsoft, Intel, BBC, and others. C2PA defines how cryptographically signed content credentials can be embedded into image, audio, and video files, creating a verifiable provenance chain.
C2PA metadata travels with the file and can be read by any compatible tool, regardless of where the content ends up. A C2PA-compliant viewer can display a badge indicating the content was generated by a specific AI tool, when it was created, and whether it has been subsequently modified.
Several major AI tools already embed C2PA credentials by default:
- Adobe Firefly — all generated content includes C2PA content credentials
- DALL-E 3 (via ChatGPT and the API) — embeds C2PA metadata in generated images
- Microsoft Designer and Bing Image Creator — C2PA compliant
- Midjourney — C2PA support in development; currently does not embed by default
- Stable Diffusion — no native C2PA embedding; requires third-party tools
If you are using tools that do not embed C2PA metadata automatically, you can add EXIF metadata manually to declare AI origin. The EXIF "ImageDescription" or "UserComment" fields can include text stating the AI origin, though this is less robust than a cryptographic C2PA signature. Several open-source tools (such as c2pa-tool by the C2PA working group) allow post-generation embedding of content credentials.
Which Tools Create Obligations Under Article 50
The following commonly used AI tools generate content that falls under the Article 50 disclosure requirements when published to EU audiences:
Image Generation
- Midjourney — realistic and stylised images; visible label required, C2PA embedding not yet automatic
- DALL-E 3 — realistic images; C2PA metadata embedded by default via OpenAI
- Stable Diffusion (all variants including SDXL, Flux) — visible label required; machine-readable requires manual steps
- Adobe Firefly — C2PA embedded; still requires visible label on publication
- Canva AI — using Magic Media or similar; check whether C2PA is embedded in your export
Audio Generation
- ElevenLabs — AI voice cloning and generation; visible disclosure required for any synthetic audio published on your site
- Murf, Descript, Play.ht — similar voice synthesis tools; same obligations apply
Video Generation
- HeyGen — AI avatar video creation; strong disclosure obligations, especially where a synthetic human presenter is used
- Sora (OpenAI) — video generation from text; visible disclosure required
- Runway ML, Pika — AI video creation and editing tools; disclosure required for published content
- Synthesia — AI avatar presenters; particularly subject to the deepfake-specific rules below
Deepfake-Specific Rules Under Article 50(4)
Article 50(4) sets out strengthened obligations specifically for content that depicts real people — either their likeness, voice, or characteristic behavior — in a way the person depicted did not actually perform. This is the EU AI Act's targeted response to deepfakes.
Under Article 50(4), when AI-generated content realistically depicts a real, identifiable person — a named individual, a public figure, a private person — the disclosure must be even more prominent than the general standard. The regulation does not specify a exact format, but guidance from the European AI Office suggests the label should be visible without the user needing to hover over, click through, or search for it.
Practical test for Article 50(4) applicability: Would a reasonable person, seeing this content in isolation, believe that the depicted person actually said, did, or was present in the scenario shown? If yes — whether the content features a CEO giving a fake statement, a product testimonial featuring a synthetic version of a real customer, or any AI-generated content depicting a real human — the deepfake disclosure rule applies.
This applies to AI-generated testimonials using synthetic voices of real reviewers, explainer videos where a real person's likeness is replicated by an AI avatar tool, or marketing content that places a recognisable person in a scenario they did not actually participate in.
How to Add Visible Labels to AI Images on WordPress
For static images in posts and pages, the most practical approach is to add a caption or figure label directly in the WordPress editor. When inserting an image block, use the "Caption" field: "Image generated with [tool name] / AI-generated." This displays below the image in the rendered post.
For featured images, product images in WooCommerce, or banner images where captions are not standard, the options are:
- Add the label as alt text and a visible overlay using CSS (a small badge in the image corner)
- Use a WordPress plugin that automatically adds a watermark or badge to images tagged with a custom field indicating AI origin
- Add a text note below the image block within the editor, styled smaller than body text
For audio and video content hosted on your site, include a clear note in the surrounding text and in the media player description: "This audio is AI-generated" or "This video features an AI-generated presenter."
Exceptions: Art, Satire, and Parody
Article 50 includes a limited exception for content produced for the purpose of art, creative expression, satire, or parody — but this exception is narrow and applies only where the AI nature of the content is already evident from the context. A clearly surrealist AI artwork posted on a gallery site would likely fall under the exception; a realistic-looking news clip made with AI video tools would not, even if the intent is satirical.
Do not rely on the satire exception unless the artistic or satirical nature of the content is unambiguous to any viewer encountering it without additional context. When in doubt, the label costs you nothing and avoids regulatory uncertainty.
Check whether the AI-generated images and media on your site are properly labeled using legibright.eu. The checker scans your page for visible disclosure signals and flags content that may be missing the required labels before the August 2 deadline.
This article is for general information only and does not constitute legal advice. For your specific situation, consult a qualified legal professional.