AI images and the label rule: images are the ones that bite
Why AI-generated images are the strictest corner of the EU's disclosure rules, and what a label a visitor can see actually means.
Part of our guide to the EU AI disclosure rules.
This guide is not legal advice. It is a plain-language explanation of the strictest corner of the EU's AI disclosure rules. For the full picture, start with our main guide.
Why images get their own article
Most coverage of the AI Act's disclosure rules talks about text, because most people writing about it are writers. But the rules treat text and images very differently, and the difference runs in the direction almost nobody expects.
For AI-generated text, the law offers a generous exit: content that has gone through genuine human review, with a named person holding editorial responsibility, needs no label at all. Review it properly, record the review, and your AI-drafted blog carries no badge.
For images, that exemption does not exist. There is no clause that says a reviewed image needs no disclosure. If an AI-generated image on your site falls within the rules, it needs a label a visitor can see, and no amount of careful human review changes that. This is the asymmetry that catches people: businesses fixate on their blog, which the law treats leniently, while the generated hero image at the top of the same page is the thing the law actually cares about.
Which images the rule reaches
The strictest duty applies to what the Act calls deep fakes: AI-generated or manipulated images that resemble real people, places, objects or events, and would falsely appear to someone as authentic. Read that definition slowly, because it is broader than the celebrity face-swaps the word usually brings to mind.
A generated photograph of a smiling team that does not exist resembles real people and appears authentic. A rendered image of "our workshop" resembles a real place and appears authentic. The suspiciously perfect tradesman on a roofing site, the stock-style office scene the model produced on request, the product photograph of a product that was never photographed: all of these are realistic depictions of real-seeming things, presenting as though a camera was involved. That is the territory the rule was written for, and it is the territory ordinary business websites live in.
There is a softer branch for content that is "evidently artistic, creative, satirical, fictional": it still requires disclosure of its generated nature, but "in an appropriate manner" that does not spoil the work. An obviously stylised illustration, a cartoon, an abstract piece of generated art on a design blog: these need honesty, not a warning sticker. The word doing the heavy lifting is "evidently". If a reasonable visitor could mistake the image for a photograph, you are not on the soft branch.
What "a label a visitor can see" means
The Act's standard, in its own words, is that the disclosure is made "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure". For an image on a web page, first exposure is the moment the image loads in front of someone. This rules out most of the places people would prefer to put it.
Not the metadata. Content credentials and C2PA signatures are genuinely good practice, and the AI companies are required by a separate part of the same article to mark their outputs in machine-readable form. But a signature inside the file is readable by software, not by your visitor, and the visitor is who the disclosure is for.
Not the alt text. Alt text serves accessibility, and a sighted visitor never sees it.
Not a site-wide line in the footer, three scrolls below the image, saying some content may be AI-generated. That discloses nothing about anything in particular.
What works is unglamorous: a caption or an adjacent line, visible without effort, in the language of the page. "This image was generated with AI." Six words next to the picture. On an image-heavy page, a clearly placed note covering the set can be reasonable, provided a visitor actually encounters it with the images and not after them.
The fix, in practice
Walk your own site the way a stranger would. For every image that looks like a photograph, ask one question: did a camera take this? If the answer is no and the image reads as real, it needs its six words. If the answer is genuinely yes, nothing changes. If the answer is "it started as a photo and the model rebuilt half of it", treat it as generated, because that is what a visitor would feel misled about.
Then decide what you would rather do with the images that fail the test. Labelling is one answer. Replacing them with real photographs is another, and for team pages it is usually the better one, for reasons that have nothing to do with the law. A generated team photo was always writing a cheque the first client meeting has to cash.
Questions people actually ask
Does every AI image on our site need a label? The hard duty covers realistic images of real-seeming people, places or events. Evidently artistic or stylised images need honesty in an appropriate manner rather than a prominent label. The cautious practice, and ours, is simple: if a model made it, say so visibly.
Our images have C2PA credentials. Are we covered? Covered at the machine layer, not the human one. Credentials in the file are good hygiene and worth keeping, but the deployer's duty is a disclosure people can see. Do both.
What about photos we lightly edited with AI tools? Cleaning, sharpening and routine retouching of a real photograph is not the concern. The line is crossed when generation or manipulation makes the image depict something that did not happen while looking like it did.
Do images we generated before August 2026 need labels now? Under the Commission's guidance, no: synthetic content generated before 2 August 2026 does not need retroactive labelling. Regenerate it, rework it or reuse it in something newly published, and the exemption falls away. And if you cannot say which of your images predate the line, that is a record-keeping discovery worth sitting with.
Do AI product renders count? A render presented as a photograph of the product is a realistic depiction presenting as authentic, so treat it as in scope and label it. A render that is obviously a render sits closer to the artistic branch. Ask what a buyer would assume.
Can we put one disclosure on the page instead of labelling each image? For a page whose imagery is broadly generated, a clear note that visitors encounter alongside the images is a defensible reading of "clear and distinguishable". A buried line somewhere below the fold is not. Placement is the whole game.
Is there really no human-review exception for images, like the one for text? Really none. The editorial-responsibility lift in Article 50 applies to text. For images, the duty is disclosure, full stop, with only the artistic softening.
What is the actual risk if we ignore this? The transparency rules carry fines of up to €15m or 3% of worldwide turnover, with smaller companies fined at the lower figure rather than the higher. Enforcement is young. The nearer-term risk is softer and faster: a client, a journalist or a competitor asking why the team photo has eleven fingers in it.
Where we come in
Our scanner checks pages for imagery that looks generated and undisclosed, alongside the text checks, and the report tells you which pages need their six words. The scan is free, takes about a minute, and if your images are all honestly yours, it will say exactly that: swornmark.com.
This guide is not legal advice. It was drafted with AI assistance and reviewed before publication. Swornmark holds editorial responsibility for it. The images on this page, should you find any, are disclosed where they sit, because we would look like tremendous fools otherwise.
More guides
Does my website need AI disclosure?
A decision-tree guide to whether the EU's AI disclosure rules reach your website, with the questions people actually ask.
What Article 50 actually says
A clause-by-clause walk through Article 50 of the EU AI Act, quoting the text and translating it for people who run websites.
The agency problem: client sites and whose duty it is
When an agency builds and runs a client's website, whose AI disclosure duty is it? The practical answer for agency owners.
How to write a disclosure that satisfies the rules
How to write an AI disclosure that satisfies the EU rules: worked examples, placement, tone, and the review that beats any wording.
Regulators, country by country: who would actually come asking
Which national authorities enforce the EU's AI disclosure rules, country by country, and how enforcement actually reaches a business.
The state of AI disclosure in Europe, August 2026
We scanned 494 ordinary business websites in 17 EU countries, 26 days after Article 50 took effect. Under 1% label their AI content. The numbers, by country and sector, with the method.
The EU's AI disclosure rules, explained for people who run websites