What actually triggers a disclosure requirement
The statutes are written around deception risk, not around whether AI touched the file. That distinction is what saves most product catalogs from a labeling overhaul.
A generated model wearing your jacket is a synthetic depiction of a human being. A viewer could believe that person exists, was cast, and endorsed the product. That is the harm the laws target. A hero shot of the same jacket on a generated seamless-paper backdrop depicts no one, and the object shown is genuinely the object being sold.
| Image type | Disclosure generally required? | Why |
|---|---|---|
| Product on generated background | No | No synthetic human; product is real |
| AI color correction / retouching | No | Enhancement of a real capture |
| Ghost mannequin from a flat lay | No | Garment is real; no depicted person |
| Generated model wearing the product | Yes | Synthetic performer / human likeness |
| Real model's face swapped or altered | Yes | Likeness manipulation |
| Fully generated product that does not exist | Yes | Misrepresents the goods (also an FTC issue) |
| Generated lifestyle scene with bystanders | Likely | Depends on prominence of synthetic people |
Disclosure law is not the only rule in play. Long-standing advertising law in most markets requires that a product image accurately represent what ships. An AI image that adds a strap, changes a fabric weave, or invents a finish is a misrepresentation whether or not you label it "AI-generated." Labeling never cures inaccuracy.
What a compliant label looks like
Regulators have converged on two layers, and most frameworks expect both where a requirement applies: something a machine can read, and something a human can see.
Machine-readable provenance. The EU AI Act requires synthetic outputs be marked in a machine-readable format detectable as artificially generated. In practice that means one of three things:
- C2PA Content Credentials — a cryptographically signed manifest embedded in the file recording what generated it and what was edited. This is the format platforms are standardizing on, and the one that survives an audit.
- IPTC/XMP metadata — a
DigitalSourceTypefield set to a synthetic-media value, or a simpleai_generated=truetag. Cheap to add, but stripped by many CDN pipelines. - Invisible watermarking — signal embedded in pixel data that survives resizing and recompression.
Human-visible disclosure. A corner badge reading "AI-generated," a caption under the image, or a line in the listing's image-notes section. Placement matters more than wording: a disclosure buried in a footer policy page does not travel with the image into a search result or a social embed.
Test your pipeline before you trust it. Upload a C2PA-signed image to each marketplace you sell on, download the public-facing version, and check whether the manifest survived. Many image CDNs strip all metadata on transform — which means your provenance dies at the exact moment it needs to exist.
How the three regimes differ
The overlap is large but not total, and the strictest rule that applies to any of your markets is effectively your operating standard.
| EU AI Act (Art. 50) | California AI Transparency Act | New York Synthetic Performer Law | |
|---|---|---|---|
| Effective | Aug 2, 2026 | Aug 2, 2026 | Jun 9, 2026 |
| Core duty | Machine-readable marking of synthetic output | Provenance metadata + detection tooling | Clear disclosure of synthetic performers in ads |
| Primary target | Generative AI providers | Large generative systems | Advertisers |
| Product-only shots | Largely out of scope | Largely out of scope | Out of scope |
| Who a seller relies on | Tool vendor's marking | Tool vendor's marking | The brand itself |
That last row is the one merchants miss. The EU and California rules place most of the marking burden on whoever built the generative system — your vendor. New York's rule lands on the advertiser. If you run AI models in a campaign that reaches New York consumers, no vendor setting protects you; the disclosure is yours to write.
A four-step audit for an existing catalog
Most brands do not know which of their live images are synthetic, which is the real problem. Work the catalog in this order.
1. Segment by synthetic-human risk. Split the catalog into three buckets: no people, real people, generated or altered people. Only the third bucket needs a disclosure decision. In a typical apparel catalog this is a small minority of assets — on-model shots, lookbook frames, and lifestyle scenes.
2. Trace provenance. For every image in the third bucket, record which tool produced it and on what date. If your generation tool writes C2PA credentials, much of the machine-readable layer already exists and you only need to stop stripping it.
3. Fix the pipeline, not just the files. Metadata preservation has to be configured in your image transform layer, your DAM export presets, and your marketplace feed. Re-tagging files by hand while the CDN keeps stripping them is wasted work.
4. Write one disclosure standard and apply it everywhere. One sentence, one placement rule, applied to every channel. Per-platform improvisation is how inconsistencies become evidence.
Reactive approach
- Wait for a platform takedown
- Label ad hoc, per marketplace
- No record of which images are synthetic
- Metadata stripped silently at the CDN
- Legal review after publication
Standards-first approach
- Catalog segmented by synthetic-human risk
- One disclosure sentence across all channels
- Provenance recorded at generation time
- Metadata preservation verified end to end
- Policy signed off once, applied by default
Platform policies move faster than the law
Statutes set the floor. Marketplace policy sets the ceiling, and it changes without a legislative session. Amazon, Google Shopping, Meta, Pinterest, and TikTok Shop have each shipped some form of synthetic-media policy, and they are not aligned with each other or with the statutes.
Three patterns are worth planning around, because they recur across platforms regardless of how the specific wording lands:
- Automatic detection and auto-labeling. Several platforms now read C2PA credentials on upload and attach their own "AI info" badge without asking. This is generally good for you — the disclosure happens automatically and consistently — but it means your image may be labeled in ways you did not author. Know what your credentials say before a platform surfaces them to shoppers.
- Accuracy enforcement over disclosure enforcement. Marketplace takedowns of AI imagery overwhelmingly cite product misrepresentation, not missing labels. An image that shows the wrong colorway, an invented texture, or a feature the SKU does not have gets suppressed on listing-accuracy grounds. That rule predates generative AI entirely and is enforced far more aggressively.
- Main-image conservatism. Platforms hold the primary listing image to a stricter standard than secondary or lifestyle images. Where you have any doubt about a generated asset, keep it out of position one.
Because platform rules shift on their own timeline, treat your disclosure standard as a living document with a named owner and a quarterly review. A policy written once in 2026 and never revisited is how brands end up out of compliance without a single law having changed.
The operational upshot: build for the strictest platform you sell on, not the average one. Maintaining per-channel variants of the same asset with different labeling is expensive, error-prone, and creates exactly the inconsistency an enforcement action would point at.
What to write in your internal standard
A workable disclosure standard fits on one page. Longer documents do not get read, and unread policy does not survive contact with a launch deadline. Cover six things.
Scope definition. State plainly which asset types are in scope. "Any image in which a human figure was generated or materially altered by AI" is a usable line. It is narrow enough that teams can apply it without a legal call, and it captures the category the 2026 rules actually target.
The disclosure sentence. Write the exact wording once. Something like "This image features an AI-generated model." Do not let each channel improvise, and do not use hedging language — "digitally enhanced" is not a synthetic-performer disclosure and will not read as one to a regulator.
Placement rules. Specify where the visible label goes for each surface: on-image badge for social, caption for PDP galleries, ad-copy line for paid placements. Ambiguity here is where compliance quietly fails.
Metadata requirements. Name the format (C2PA preferred), the fallback (XMP DigitalSourceType), and the verification step that confirms it survived publication. Assign that verification to a specific role.
Accuracy review. Separate from disclosure: a checkpoint confirming the generated image represents the actual SKU — correct colorway, correct hardware, correct trim, no invented features. This catches the failure mode that actually triggers takedowns.
Record retention. Keep the generation tool, prompt or settings, date, and approver for every in-scope asset. If you are ever asked to demonstrate compliance, the record is the answer, and reconstructing it after the fact is close to impossible at catalog scale.
Put the accuracy review before the disclosure step in your workflow. An image that misrepresents the product is a problem you cannot label your way out of — catching it first means you never spend effort tagging an asset you are going to discard.
Why this is a smaller problem than the headlines suggest
Coverage of the 2026 rules has framed them as an existential threat to AI product imagery. For most e-commerce catalogs, they are not — because most of what AI does in a product workflow is invisible to these statutes.
Background replacement, wrinkle removal, color correction, shadow reconstruction, ghost mannequin generation, catalog-wide consistency passes — none of these depict a person, and none of them change what is being sold. They fall on the exempt side of every line the 2026 rules draw. Retouchable's workflows sit largely in that category, which is why the compliance question for most catalogs reduces to a single bucket: on-model imagery.
Handle the on-model bucket deliberately, keep your provenance metadata alive through the CDN, and the rest of the catalog carries on unchanged.