AI Image Disclosure Rules for E-Commerce in 2026

Three transparency laws landed in 2026, and the line they draw runs straight through your product catalog: synthetic people need labels, plain product shots mostly do not.

|AI compliance e-commerce product photography regulation

The rule that matters most for AI image disclosure in e-commerce is simpler than the legislation makes it look: if there is a synthetic person in the frame, you almost certainly need to disclose. If the frame contains only your product — retouched, relit, or dropped onto a generated backdrop — you usually do not.

Three regimes converged this year. New York's Synthetic Performer Disclosure Law took effect June 9, 2026. The EU AI Act's Article 50 transparency obligations became enforceable August 2, 2026, alongside California's AI Transparency Act. They differ in scope and penalty, but they point the same direction: machine-readable provenance on synthetic media, and clear labeling wherever a viewer could reasonably mistake a generated human for a real one.

What follows is a practical read of where the lines fall for product catalogs, what a compliant label actually looks like, and how to retrofit provenance onto a catalog you have already shipped. This is an operational guide, not legal advice — a lawyer in your jurisdiction should sign off before you change a policy.

What actually triggers a disclosure requirement

The statutes are written around deception risk, not around whether AI touched the file. That distinction is what saves most product catalogs from a labeling overhaul.

A generated model wearing your jacket is a synthetic depiction of a human being. A viewer could believe that person exists, was cast, and endorsed the product. That is the harm the laws target. A hero shot of the same jacket on a generated seamless-paper backdrop depicts no one, and the object shown is genuinely the object being sold.

Image typeDisclosure generally required?Why
Product on generated backgroundNoNo synthetic human; product is real
AI color correction / retouchingNoEnhancement of a real capture
Ghost mannequin from a flat layNoGarment is real; no depicted person
Generated model wearing the productYesSynthetic performer / human likeness
Real model's face swapped or alteredYesLikeness manipulation
Fully generated product that does not existYesMisrepresents the goods (also an FTC issue)
Generated lifestyle scene with bystandersLikelyDepends on prominence of synthetic people
The independent trap

Disclosure law is not the only rule in play. Long-standing advertising law in most markets requires that a product image accurately represent what ships. An AI image that adds a strap, changes a fabric weave, or invents a finish is a misrepresentation whether or not you label it "AI-generated." Labeling never cures inaccuracy.

What a compliant label looks like

Regulators have converged on two layers, and most frameworks expect both where a requirement applies: something a machine can read, and something a human can see.

Machine-readable provenance. The EU AI Act requires synthetic outputs be marked in a machine-readable format detectable as artificially generated. In practice that means one of three things:

  • C2PA Content Credentials — a cryptographically signed manifest embedded in the file recording what generated it and what was edited. This is the format platforms are standardizing on, and the one that survives an audit.
  • IPTC/XMP metadata — a DigitalSourceType field set to a synthetic-media value, or a simple ai_generated=true tag. Cheap to add, but stripped by many CDN pipelines.
  • Invisible watermarking — signal embedded in pixel data that survives resizing and recompression.

Human-visible disclosure. A corner badge reading "AI-generated," a caption under the image, or a line in the listing's image-notes section. Placement matters more than wording: a disclosure buried in a footer policy page does not travel with the image into a search result or a social embed.

Pro Tip

Test your pipeline before you trust it. Upload a C2PA-signed image to each marketplace you sell on, download the public-facing version, and check whether the manifest survived. Many image CDNs strip all metadata on transform — which means your provenance dies at the exact moment it needs to exist.

How the three regimes differ

The overlap is large but not total, and the strictest rule that applies to any of your markets is effectively your operating standard.

EU AI Act (Art. 50)California AI Transparency ActNew York Synthetic Performer Law
EffectiveAug 2, 2026Aug 2, 2026Jun 9, 2026
Core dutyMachine-readable marking of synthetic outputProvenance metadata + detection toolingClear disclosure of synthetic performers in ads
Primary targetGenerative AI providersLarge generative systemsAdvertisers
Product-only shotsLargely out of scopeLargely out of scopeOut of scope
Who a seller relies onTool vendor's markingTool vendor's markingThe brand itself

That last row is the one merchants miss. The EU and California rules place most of the marking burden on whoever built the generative system — your vendor. New York's rule lands on the advertiser. If you run AI models in a campaign that reaches New York consumers, no vendor setting protects you; the disclosure is yours to write.

A four-step audit for an existing catalog

Most brands do not know which of their live images are synthetic, which is the real problem. Work the catalog in this order.

1. Segment by synthetic-human risk. Split the catalog into three buckets: no people, real people, generated or altered people. Only the third bucket needs a disclosure decision. In a typical apparel catalog this is a small minority of assets — on-model shots, lookbook frames, and lifestyle scenes.

2. Trace provenance. For every image in the third bucket, record which tool produced it and on what date. If your generation tool writes C2PA credentials, much of the machine-readable layer already exists and you only need to stop stripping it.

3. Fix the pipeline, not just the files. Metadata preservation has to be configured in your image transform layer, your DAM export presets, and your marketplace feed. Re-tagging files by hand while the CDN keeps stripping them is wasted work.

4. Write one disclosure standard and apply it everywhere. One sentence, one placement rule, applied to every channel. Per-platform improvisation is how inconsistencies become evidence.

Reactive approach

  • Wait for a platform takedown
  • Label ad hoc, per marketplace
  • No record of which images are synthetic
  • Metadata stripped silently at the CDN
  • Legal review after publication

Standards-first approach

  • Catalog segmented by synthetic-human risk
  • One disclosure sentence across all channels
  • Provenance recorded at generation time
  • Metadata preservation verified end to end
  • Policy signed off once, applied by default

Platform policies move faster than the law

Statutes set the floor. Marketplace policy sets the ceiling, and it changes without a legislative session. Amazon, Google Shopping, Meta, Pinterest, and TikTok Shop have each shipped some form of synthetic-media policy, and they are not aligned with each other or with the statutes.

Three patterns are worth planning around, because they recur across platforms regardless of how the specific wording lands:

  • Automatic detection and auto-labeling. Several platforms now read C2PA credentials on upload and attach their own "AI info" badge without asking. This is generally good for you — the disclosure happens automatically and consistently — but it means your image may be labeled in ways you did not author. Know what your credentials say before a platform surfaces them to shoppers.
  • Accuracy enforcement over disclosure enforcement. Marketplace takedowns of AI imagery overwhelmingly cite product misrepresentation, not missing labels. An image that shows the wrong colorway, an invented texture, or a feature the SKU does not have gets suppressed on listing-accuracy grounds. That rule predates generative AI entirely and is enforced far more aggressively.
  • Main-image conservatism. Platforms hold the primary listing image to a stricter standard than secondary or lifestyle images. Where you have any doubt about a generated asset, keep it out of position one.
Practical consequence

Because platform rules shift on their own timeline, treat your disclosure standard as a living document with a named owner and a quarterly review. A policy written once in 2026 and never revisited is how brands end up out of compliance without a single law having changed.

The operational upshot: build for the strictest platform you sell on, not the average one. Maintaining per-channel variants of the same asset with different labeling is expensive, error-prone, and creates exactly the inconsistency an enforcement action would point at.

What to write in your internal standard

A workable disclosure standard fits on one page. Longer documents do not get read, and unread policy does not survive contact with a launch deadline. Cover six things.

Scope definition. State plainly which asset types are in scope. "Any image in which a human figure was generated or materially altered by AI" is a usable line. It is narrow enough that teams can apply it without a legal call, and it captures the category the 2026 rules actually target.

The disclosure sentence. Write the exact wording once. Something like "This image features an AI-generated model." Do not let each channel improvise, and do not use hedging language — "digitally enhanced" is not a synthetic-performer disclosure and will not read as one to a regulator.

Placement rules. Specify where the visible label goes for each surface: on-image badge for social, caption for PDP galleries, ad-copy line for paid placements. Ambiguity here is where compliance quietly fails.

Metadata requirements. Name the format (C2PA preferred), the fallback (XMP DigitalSourceType), and the verification step that confirms it survived publication. Assign that verification to a specific role.

Accuracy review. Separate from disclosure: a checkpoint confirming the generated image represents the actual SKU — correct colorway, correct hardware, correct trim, no invented features. This catches the failure mode that actually triggers takedowns.

Record retention. Keep the generation tool, prompt or settings, date, and approver for every in-scope asset. If you are ever asked to demonstrate compliance, the record is the answer, and reconstructing it after the fact is close to impossible at catalog scale.

Pro Tip

Put the accuracy review before the disclosure step in your workflow. An image that misrepresents the product is a problem you cannot label your way out of — catching it first means you never spend effort tagging an asset you are going to discard.

Why this is a smaller problem than the headlines suggest

Coverage of the 2026 rules has framed them as an existential threat to AI product imagery. For most e-commerce catalogs, they are not — because most of what AI does in a product workflow is invisible to these statutes.

3Regimes live in 2026
0Labels needed for pure product shots
2Layers in a compliant label
1Standard to write and reuse

Background replacement, wrinkle removal, color correction, shadow reconstruction, ghost mannequin generation, catalog-wide consistency passes — none of these depict a person, and none of them change what is being sold. They fall on the exempt side of every line the 2026 rules draw. Retouchable's workflows sit largely in that category, which is why the compliance question for most catalogs reduces to a single bucket: on-model imagery.

Where AI touches a typical apparel catalog
Background / cleanup
Exempt
Color & consistency
Exempt
Ghost mannequin
Exempt
Generated on-model
Disclose

Handle the on-model bucket deliberately, keep your provenance metadata alive through the CDN, and the rest of the catalog carries on unchanged.

Frequently Asked Questions

Do I have to disclose AI-generated product images on Shopify?

Shopify itself does not impose a blanket AI-image disclosure requirement, but the law of the markets you sell into does. Pure product shots — your real product on a generated background, or retouched with AI — generally require no disclosure. Images showing an AI-generated person wearing or holding your product do, particularly for EU, California, and New York audiences.

Does AI retouching count as an AI-generated image?

Under the 2026 transparency rules, routine retouching of a real photograph — color correction, wrinkle removal, background cleanup, shadow work — is treated as enhancement rather than synthetic generation, and is generally out of scope. What matters is whether the image depicts a synthetic person or misrepresents the product, not whether a model was involved in producing it.

What is C2PA and do I need it?

C2PA (Content Credentials) is an open standard for cryptographically signed provenance metadata embedded in an image file. It is the format the EU AI Act’s machine-readable marking requirement is most cleanly satisfied by, and the one major platforms are adopting. If you publish AI-generated human imagery into regulated markets, C2PA is the most durable way to carry that marking.

What happens if my CDN strips the metadata?

Then your machine-readable disclosure does not exist for the version customers actually see. Verify this directly: publish a signed image, download the public URL, and inspect it. Many image transform pipelines strip all metadata on resize by default, and the fix is a configuration change in the transform layer rather than a re-tagging of source files.

Who is liable — me or the AI tool I used?

It depends on the regime. The EU AI Act and California’s transparency law place most of the marking obligation on the provider of the generative system. New York’s synthetic performer law places disclosure squarely on the advertiser. If you run campaigns featuring AI-generated people, assume the disclosure duty is yours and confirm with counsel in your jurisdiction.

Most of your catalog never needed a label

Retouchable handles the background, color, and cleanup work that sits safely outside the 2026 disclosure rules — so your product imagery stays fast to produce and simple to publish.

Try Retouchable Free No credit card required