The EU AI Act reaches Shopify merchants on 2 August 2026, and most of what you have read about it is probably overstated. Article 50, the transparency chapter that covers AI-generated content, does create real duties for stores that sell into the EU with AI-generated product imagery. But the loudest claim circulating in app marketing right now ("merchants must watermark every AI image or face €15 million fines") mixes up two different obligations that the law assigns to two different parties. One of them is yours. One of them is not.
We spent time with the official Article 50 text so you don't have to, and this post separates the two. We are not lawyers, and this is not legal advice. We build Viking Watermark, which includes an AI Generated disclosure badge, so we have an interest here. That's exactly why we'd rather get the scope right than scare you into installing something.
Quick facts
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) applies from 2 August 2026. It puts machine-readable marking of AI outputs on the providers of AI systems (the tool vendors), and puts a disclosure duty on deployers (including merchants) only when AI-generated or AI-manipulated content constitutes a deep fake. Penalties for transparency violations can reach €15 million or 3 percent of global annual turnover, whichever is higher. Separately, New York's Synthetic Performer Disclosure Law took effect on 9 June 2026 and covers advertisements shown to New York audiences that feature AI-generated human likenesses, with civil penalties of $1,000 for a first violation and $5,000 for each one after that.
What is Article 50 of the EU AI Act?
Article 50 is the transparency chapter of the EU AI Act. It requires that people are told when they interact with an AI system, that AI-generated audio, image, video, and text outputs are marked in a machine-readable format, and that deep fake content is disclosed as artificially generated. It enters into application on 2 August 2026, per the official Article 50 text.
The part that matters for a store is that the article splits its duties between providers and deployers. A provider is whoever builds and sells the AI system: the image model, the generation tool, the upscaler. A deployer is whoever uses that system in a professional context. A Shopify merchant generating product visuals with Midjourney or a built-in AI photo tool is a deployer. And the deployer duties are narrower than the provider duties. Much narrower.
Do Shopify merchants have to watermark AI-generated product images?
No, not in the way the phrase suggests. The machine-readable marking requirement falls on the maker of the AI tool that generated the image, not on the store that used it. Your job is simpler: tell shoppers clearly that an image is AI-made when it could pass for a real photo. The law calls this the deployer disclosure duty (Article 50(4), for anyone who wants the citation). It doesn't prescribe a watermark.
This distinction gets flattened constantly. Really. The €15 million headline number is the law's ceiling for serious transparency violations, and the marking duty it usually gets attached to is your image tool's problem, not yours. Does that mean a store can ignore the whole thing? No. If your AI-generated lifestyle scene would read as an authentic photograph to a normal shopper, the disclosure part is yours, and it goes live on 2 August 2026.
The machine-readable watermark is your AI tool's homework. The visible disclosure, when the image would pass as real, is yours.
One more honesty note, since we publish a whole post on what protection apps cannot do: no Shopify badge app, ours included, makes you "EU AI Act compliant" by itself. A visible badge is one reasonable way to deliver the disclosure the law asks for. It is not the metadata-level marking the AI tool itself has to do, and Viking Watermark does not embed forensic or steganographic marks. Any app that sells you full compliance in one click is overclaiming.
When does a product image trigger the disclosure duty?
The Act's deep fake concept covers AI-generated or manipulated image, audio, or video content that resembles real persons, objects, places, entities, or events and would falsely appear authentic or truthful to a person. The definition is kinda broad on first read. In a product photography context, the practical question is: would a reasonable shopper believe this is a real photograph of a real scene?
Likely inside the duty: an AI-generated model wearing your apparel, presented as a normal product photo. A real product composited into an AI-generated apartment that looks like a real location. An AI-fabricated "customer photo". Likely outside it: obviously stylized AI illustrations, and standard assistive editing. The law explicitly carves out AI that just helps with normal editing or doesn't substantially change the input, so background cleanup, color correction, and dust removal are not what it is hunting.
But here is the part that annoys us about this category. App blogs have started writing about product photos the way tabloids write about celebrity deep fakes, as if every AI-touched thumbnail is a €15 million liability. Why frame it that way? Because fear installs apps. The honest read is duller: most catalogs need a disclosure on a subset of images, applied consistently, and that's it. The Commission's code of practice work on labelling is still taking shape, so the edges will keep moving. Build a workflow, not a panic.
What does the New York synthetic performer law add?
New York's Synthetic Performer Disclosure Law took effect on 9 June 2026. It requires a conspicuous disclosure when a visual or audiovisual advertisement distributed to a New York audience features an AI-generated synthetic performer, meaning a fabricated human likeness that does not depict a real person. Civil penalties run $1,000 for a first violation and $5,000 per subsequent violation, per the state's announcement.
Notice how much narrower this is than the coverage suggests. It applies to advertisements. It applies to human likenesses. An AI-generated image of your ceramic mug on a kitchen counter, with no person in frame, is outside this law entirely. An AI-generated model wearing your jacket in a paid social ad shown to New Yorkers? That's squarely inside it.
| EU AI Act, Article 50(4) | New York synthetic performer law | |
|---|---|---|
| In effect | 2 August 2026 | 9 June 2026 |
| Covers | AI content that would falsely appear authentic (deep fakes), wherever shown | Ads with AI-generated human likenesses shown to NY audiences |
| Who owes the duty | Merchants using the content disclose; AI tool makers mark outputs machine-readably | Whoever produces or creates the advertisement |
| Product image with no person | Can apply, if it would pass as an authentic photo | Does not apply |
| Penalties | Up to €15M or 3% of global turnover | $1,000 first violation, $5,000 each after |
How do you add a visible AI disclosure on Shopify?
The lowest-friction pattern is a corner badge on the affected images plus a one-line note in the product description. Shopify has no native AI disclosure feature, so it is theme code or an app. We built the AI Generated badge into Viking Watermark's library of 100+ badges precisely because disclosure rules were already forming when we shipped, and it has become one of the more common things merchants ask us about. Tag the affected products (a tag like ai-image works), point the badge rule at that tag, done. The same scope controls we describe in our bulk watermarking guide apply to badges, and if new AI renders keep entering the catalog, the same logic behind auto-watermarking new uploads saves you from re-doing it by hand every month.
Two practical notes. First, badges and watermarks are different tools: a badge is a corner overlay for communication, a watermark is a brand mark for attribution. Our product badges guide walks through where each breaks. Second, whatever app you pick (there are several in the 2026 watermark app roundup), run it through the permissions audit first. A compliance badge should not cost you read access to your customer data.
For the fuller operational walkthrough (what counts as AI-generated in practice, mixed catalogs, per-image badging), we keep a dedicated guide on the Viking Watermark blog: adding the AI Generated disclosure badge.
What should you do before 2 August 2026?
Three steps, none of which take more than an afternoon.
- 01Inventory your AI usage. List which product images were AI-generated or substantially AI-modified, and which tools produced them. This list is also your evidence trail if anyone ever asks. Most stores discover the list is shorter than they feared.
- 02Sort images by the authenticity test. Would a shopper take this for a real photograph of a real scene or person? If yes, it needs a disclosure. If it is obviously stylized, or the AI only did standard cleanup, it likely doesn't. When an image sits on the line, disclose. The badge costs you nothing.
- 03Wire the disclosure into your workflow. Tag affected products, apply the badge by tag, add the one-line description note, and make tagging part of every future AI-image upload. A disclosure process that depends on someone remembering is a process that fails by October.
And check your ad pipeline separately. If you run paid social with AI-generated people in the creative and any of it reaches New York, the ad-level disclosure is its own task with its own deadline, which has already passed.
Frequently asked questions
Does the EU AI Act apply to my Shopify store if I am not in the EU?
It can. The Act applies to organisations placing AI systems on the EU market or using AI output in a professional context reaching the EU, regardless of where the business is based. If you market to EU customers with AI-generated imagery that would pass as authentic, the disclosure duty is worth taking seriously.
Who has to add the machine-readable watermark under the EU AI Act?
The provider of the AI system that generates the content. Tools generating synthetic images must mark their outputs in a machine-readable format under Article 50(2). Merchants using those tools are deployers and carry the visible disclosure duty for deep fake content instead.
Is a visible badge enough for EU AI Act compliance?
A clear visible disclosure at first exposure is what the AI Act asks of merchants using AI content, and a badge plus a description note is a reasonable way to deliver it. No badge app makes a store compliant by itself, and the Commission's labelling guidance is still evolving. Verify against your own legal advice.
Do AI-edited photos need disclosure, or only fully AI-generated ones?
The duty attaches to content that is AI-generated or AI-manipulated and would falsely appear authentic. Standard assistive editing that does not substantially alter the input, like background removal or color correction, is explicitly carved out. A composite that fabricates a believable scene is a different story.
What are the penalties if a merchant skips the disclosure?
The EU AI Act allows fines up to €15 million or 3 percent of global annual turnover for transparency violations, with proportionality baked into enforcement. New York's synthetic performer law carries $1,000 for a first violation and $5,000 for each subsequent one. Neither framework is aimed at good-faith stores with a working disclosure process.
Does New York's law cover AI product images without people in them?
No. It covers advertisements featuring AI-generated synthetic performers, meaning fabricated human likenesses. A personless AI product render is outside that law, though it may still fall under the EU AI Act's disclosure duty if it would pass as an authentic photo to EU shoppers.
The disclosure layer is the newest slice of a wider discipline we cover in the honest guide to Shopify product image protection: knowing exactly what each tool does, what it doesn't, and which duties are actually yours. Regulators just handed the overclaiming half of this app category a €15 million reason to keep exaggerating. We think accuracy will age better.
