AI content on your store now needs a label. The EU AI Act just made it law.

On 2 August 2026, the transparency rules in Article 50 of the EU AI Act became applicable. If you run an online store, use AI to write copy or generate images, embed a chatbot, or post AI-assisted content on social, some of this now applies to you. The good news: most of it is lighter than the headlines suggest, and a lot of ordinary AI product content is not caught at all. Here is the honest version, with extra attention on the two places ecommerce brands get caught most: your website and your social accounts.
1. What actually changed on 2 August 2026*1
The EU AI Act (Regulation (EU) 2024/1689) came into force in August 2024, but its obligations switch on in stages. The transparency duties in Article 50 are the ones that became applicable on 2 August 2026. They are about one thing: people should be able to tell when they are dealing with AI, whether that is a bot, a synthetic image, or an AI-written article.
There is a short grace window worth knowing. The machine-readable marking duty for generative systems already on the market runs until 2 December 2026, and content generated and published before that date does not have to be relabeled retroactively.
2. The four rules, in plain English*2

Article 50 sets out four transparency obligations. Two land on providers (the companies that build the AI system), and two land on deployers (the companies that use it, which is usually you).
- Chatbots, 50(1), provider: if an AI system talks directly to people, they must be told they are dealing with an AI, unless it is obvious.
- Synthetic content marking, 50(2), provider: AI that generates audio, image, video, or text must mark its output in a machine-readable format so it is detectable as artificially generated. This is the invisible watermark or metadata duty, and it sits with the AI vendor, not with you.
- Emotion and biometric categorization, 50(3), deployer: if you run a system that reads emotions or sorts people by biometric traits, you must tell the people exposed to it.
- Deepfakes and public-interest text, 50(4), deployer: if you publish a deepfake (synthetic image, audio, or video that looks authentic), you must disclose it. If you publish AI-generated text to inform the public on a matter of public interest, you must disclose that too.
Whatever the case, the disclosure has to be "clear and distinguishable" and given at the latest when a person first sees or interacts with the content (50(5)). The Commission's guidance is blunt about one thing: a notice buried in a page footer or in the source code does not count.
3. Are you a provider or a deployer?
This distinction decides what you owe, so get it right first.
If you use ChatGPT, Claude, Midjourney, or a copywriting tool to make content, you are a deployer. The heavy technical duty, marking every output in a machine-readable way, belongs to the AI vendor as the provider. Your duty is narrower: disclose in the specific cases the law names.
If you build and ship an AI feature of your own, for example your own chatbot or your own image generator inside your app, you are also a provider for that feature, and the chatbot-disclosure and marking duties attach to you as well.
4. Your ecommerce website*3
Walk your own storefront and there are really three surfaces to think about.
The chat widget. An AI shopping assistant, an AI support agent, or a "help me choose" bot must let a shopper tell it is AI, unless that is already obvious from the context. In practice this is a single line near the chat input. If you built the assistant yourself you also carry the provider duties for it; if you dropped in a third-party widget, confirm the vendor labels it.
Homepage and product copy. Here is the nuance the scary headlines skip. Ordinary AI-written product descriptions, category blurbs, and homepage marketing copy are generally not "text published to inform the public on a matter of public interest," so the deployer disclosure duty in 50(4) usually does not force a label on your product pages. Where you do need to think harder: content that touches health, consumer safety, finance, or science, which can fall inside the public-interest scope.
Product images and visuals. Two questions decide this. Is it a deepfake, meaning a synthetic image that resembles a real person, place, or event and would falsely seem authentic? If yes, disclose it. Is it an ordinary AI product image that does not impersonate a real person or event? Then it is generally not a deepfake. Per the Commission's own examples, a real product photographed against an AI-generated background is not a deepfake, as long as the ad does not mislead about how the product actually looks. The AI tool still marks the file in metadata as the provider, but you are not obliged to stamp a visible "AI" badge on every catalog image.
5. Your brand's social media accounts*4
Social is where ecommerce brands get caught most often, because the content that performs well on social is exactly the content the law is watching: synthetic faces, voices, and manipulated video. If any of these appear in your posts or paid ads, the deployer deepfake duty applies and you must disclose, every time.
- AI spokespeople and virtual influencers. The trigger is whether the content qualifies as a deepfake. An AI version of a real influencer, or a realistic synthetic person passing as an authentic, real individual, needs disclosure. A clearly fictional or obviously synthetic character that is not passing as real is generally not a deepfake, so it is generally not caught.
- Synthetic celebrity or athlete endorsements. An AI-generated image or video of a famous person promoting your product will, in the Commission's words, generally be subject to the transparency obligation. Note that intent to deceive is not required.
- Face-swaps, AI voiceovers of real people, "re-created" events. All deepfakes, all disclosable.
- Clearly unreal creative. A talking animal, a robot voice, an obvious fantasy scenario, or an "alien" mascot is not a deepfake, because nobody would take it as authentic. These do not need the label.
One more thing that catches brands off guard: the major platforms (Meta, TikTok, YouTube) run their own AI-labeling policies that are often stricter than the law and apply worldwide, not just in the EU. Treat platform policy as the floor and Article 50 as the legal backstop.
6. AI-generated reports and analytics*5
If a report is generated or assisted by AI and it is published to inform the public on a matter of public interest, it needs an AI disclosure. Internal dashboards and private client reports are a lighter case, but a plain disclosure line is cheap insurance and increasingly expected. This is why every RivalSweeper report already carries an AI-assistance note.
7. The exceptions that actually help you*6
- Assistive editing. AI used for standard editing that does not substantially alter your content, for example grammar fixes or minor touch-ups, is exempt from the marking duty.
- Editorial control. AI-generated text that goes through human review, where a person or organization holds editorial responsibility, is exempt from the public-interest text disclosure. A real editor in the loop is a real defense.
- Obvious AI. If it is plainly obvious to a reasonable person that they are dealing with AI, the chatbot disclosure is not separately required.
8. What it costs to get wrong*7
Breaching Article 50 sits in the middle penalty tier of the Act: up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99). For SMEs and startups, the lower of the two figures applies. It is not the top-tier fine reserved for banned uses, but it is not a rounding error either.
9. Your Article 50 checklist for an ecommerce brand
Label your chatbot
Add a one-line "you are chatting with an AI assistant" note to any bot on your site.
Check your AI vendors mark outputs
Ask, in writing, whether their tools watermark or tag content as AI-generated.
Disclose deepfakes in social and ads
Deepfake-style media (a synthetic double of a real person, a cloned voice, a manipulated real event) gets a visible label.
Keep a human editor on public-interest text
Editorial responsibility is a genuine exemption. Record that you have it.
Put a disclosure on published AI reports
A single plain line on any public, AI-assisted report or article.
Read each platform's AI policy
Meta, TikTok, and YouTube rules are usually stricter than the law and global.
Make labels clear, not buried
Visible and easy to spot. Footer text or source-code notes do not satisfy the rule.
Don't over-label ordinary content
Plain AI product copy and non-impersonating product images are generally out of scope.
10. How RivalSweeper handles it
We took the same medicine. Every RivalSweeper report and every AI-assisted page in the platform now carries a plain disclosure that certain content is generated or assisted by AI, in line with Article 50. It is a small line of text, and it is the honest thing to show a customer.
More detail on the starred points *
*1 - Staged application. The AI Act applies in phases: prohibited-practice rules from February 2025, general-purpose AI model rules from August 2025, and the Article 50 transparency obligations from 2 August 2026. Providers of generative systems already on the market have until 2 December 2026 to meet the machine-readable marking duty. Back to section 1.
*2 - Provider vs deployer, and the carve-outs. A "provider" develops an AI system and puts it on the market; a "deployer" uses one under its own authority. Article 50 also carves out AI systems authorized by law for law-enforcement purposes from several of the duties. Paragraph 50(6) confirms these transparency rules do not replace the stricter obligations that apply to high-risk AI systems. Back to section 2.
*3 - Why most product content is out of scope. The deployer text duty in 50(4) is limited to text published "to inform the public on matters of public interest." A product description selling a jacket is not that. The provider marking duty in 50(2) still applies at the tool level, which is the AI vendor's responsibility, not yours. This is a deliberately narrow reading of the law, not a loophole. Back to section 4.
*4 - The deepfake test, applied to ads. A deepfake (Article 3(60)) is AI content that resembles an existing person, object, place, or event and would falsely appear authentic. The Commission's advertising guidance draws the line clearly: a synthetic image of a real celebrity or athlete promoting a product is in scope; a robot voice or a cartoon animal is not; a real product on an AI background is not, unless it misleads about the product itself. Artistic or satirical deepfakes still need a disclosure, but it can be placed so it does not spoil the piece. Back to section 5.
*5 - When a report is "public interest." A market report you publish openly can qualify; a private, client-only report is a lighter case. Because the line is fuzzy, a short standing disclosure on anything AI-assisted is the low-cost, defensible choice. Back to section 6.
*6 - Editorial control in practice. The text exemption needs a responsible editorial entity with authority to approve, alter, or reject the substance of the content. A rubber-stamp does not qualify; a genuine review process, documented, does. Back to section 7.
*7 - The penalty tiers. Article 99 sets three bands. Banned practices carry the top fine of up to €35 million or 7% of worldwide turnover. Most other obligations, including Article 50, sit at up to €15 million or 3%. Supplying incorrect information to authorities is up to €7.5 million or 1%. For SMEs and startups, the lower figure of the applicable band is used. Back to section 8.
References
- Article 50, Regulation (EU) 2024/1689 (EU AI Act): artificialintelligenceact.eu/article/50
- European Commission, Guidelines on transparency obligations (Article 50): digital-strategy.ec.europa.eu
- European Commission FAQ, Transparency obligations under Article 50: Article 50 FAQ
- European Commission, Code of Practice on Transparency of AI-generated Content: Code of Practice
Not legal advice. This article is general information, not a substitute for advice from a lawyer with specific expertise in EU AI regulation and your market. Your obligations depend on your exact setup, content, and jurisdiction. Before you rely on any of the above, have a qualified professional review your situation.
AI transparency note: this article was drafted with AI assistance and reviewed by the RivalSweeper team, which holds editorial responsibility for it, in the spirit of EU AI Act Article 50.
