The AI Act's Labelling Rules Are Live. Your Packshot Is Probably Fine. Your Model Is Not.
Since 2 August, a photorealistic AI model holding your product has very likely needed a visible AI label. The packshot beside her very likely does not. That single line is the whole rule for beauty, and it is not the line most of the coverage has drawn.
The transparency rules in Article 50 of Regulation (EU) 2024/1689 became applicable on Sunday 2 August 2026. For a brand or an agency, enforcement comes from your national market surveillance authority rather than from Brussels. The ceiling under Article 99(4) is 15 million euros or 3 per cent of worldwide annual turnover, whichever is higher, with the reverse for SMEs.
One clarification before anything else, because it is the freshest source of confusion. If you heard this summer that the AI Act was delayed, that is true, and it is not about this. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July and pushed the high-risk compliance dates back to 2 December 2027 and 2 August 2028. Article 50 was left exactly where it stood. The Commission announced on 31 July that from 2 August the AI Office, national competent authorities and the European Data Protection Supervisor would begin enforcing the new transparency rules. The delay headlines are a large part of why so many beauty image libraries are still sitting unlabelled.
The label is for deep fakes, not for AI
The common misreading is that every AI-assisted image now carries a mark. It does not. The duty attaches to deep fakes, which Article 3(60) defines as content resembling existing persons, objects, places, entities or events that would falsely appear authentic or truthful.
The Commission's guidelines of 20 July 2026, document C(2026) 5054 final, turn that definition into a test with four criteria that have to be met together. At paragraph 113: the content resembles something, and the resemblance is appreciable; the thing it resembles exists; that thing is a person, object, place, entity or event; and the result would falsely appear to a person to be authentic or truthful. Separately, at paragraph 112, the duty only bites where an AI system is used by a deployer for professional purposes to generate or manipulate image, audio or video content.
That last criterion, the false appearance, is judged objectively against the reasonably foreseeable audience. Paragraph 114 is explicit that the assessment does not require any intention to deceive.
For beauty the operative word is truthful, not authentic. Nobody disputes that a before-and-after is a real photograph. They dispute whether it shows what the product does.
Where your assets actually fall
The guidelines' own advertising examples map cleanly onto a normal beauty workflow.
Very likely outside. Colour correction. Replacing or extending a background for aesthetic reasons. Arranging existing products in a composition. Re-scaling. A real bottle shot against an AI background sits outside, provided the ad is not likely to mislead about how the product actually looks. The Commission's reasoning at paragraph 116 is that these have only a minor impact on how the content is perceived.
Very likely inside. A product image edited, in the Commission's own words, to appear more appealing or with improved quality than in real life. If the AI has deepened the colour, cleaned the glass or smoothed the finish beyond what is on the shelf, you are in.
The practical test is the one your artwork QA already applies: if the pack in the image is faithful to the pack in the box, you are almost certainly fine.
The part nobody is covering: your model
On the third criterion, the categories, the guidelines list at paragraph 113 expressly includes realistic AI-generated human avatars or personas. A synthetic model does not have to be a real, named person to count.
Photorealism is not on its own decisive. Paragraph 114 says a high degree of photorealism makes it more likely that content should be treated as a deep fake, while stopping short of making it determinative.
What closes the gap for beauty is the Commission's own example list. An AI-manipulated video featuring a realistic synthetic influencer testing out a sponsored real product is given as content that is not evidently artistic or fictional, and therefore does not get the lighter treatment under Article 50(4). Advertisements might be regarded as evidently creative or fictional in certain specific situations, but paragraph 122 makes the assessment case by case, and a campaign shot selling a product will rarely be one of them.
Synthetic models have become routine in beauty campaign work. Since 2 August, those images have very likely needed a visible disclosure, and the packshots beside them very often do not.
Who carries the duty
The duty sits with the deployer, the party under whose authority the system is used. Paragraph 12 of the guidelines puts an agency using AI in production squarely in that role, and it stays there even when it works through freelancers. A brand that merely commissions, without any control over whether and how AI is used, is not the deployer.
In practice that is rarely clean. A normal campaign has the advertiser setting the parameters and the agency holding day to day control. Our reading is that this points at responsibility shared between them rather than a duty either side can brief away. The guidelines do not use the word shared, so treat that as this magazine's analysis rather than the Commission's, and settle it in the contract, not after a complaint. The same paragraph asks deployers to take proportionate steps, contractual conditions among them, to keep the label intact as an asset moves down a distribution chain.
One trap worth knowing: paragraph 117 states that a deployer cannot rely on the machine-readable marking embedded in the content by the provider. A person has to be able to see the label.
What the mark has to look like
The Regulation prescribes no design. Article 50(5) requires only that the information is clear and distinguishable, at the latest at first exposure. The guidelines define the failure instead: at paragraph 142, a disclosure fails where it can be easily overlooked under normal viewing, and terms of use that are often not read are named as an example of exactly that. A mark on the image can pass. A line in the terms of use cannot.
The voluntary Code of Practice on Transparency, published in final form on 10 June 2026, does prescribe a design. Its Measure 1.1(a) builds the mark around the capitalised acronym AI as the main visual element, and the Commission publishes a free icon set for it, in three types and four colour variants, with no attribution required.
Signing is optional. Non-signatories are expected to show compliance by other adequate means, and adherence counts as a mitigating factor if a fine is set. It is no longer a fringe option either. The Commission reported on 31 July that around 190 organisations had signed, the major model providers among them, and on the deployer side names as close to this industry as Bulgari. Two signatory task forces, one for providers and one for deployers, start work in September, which is where the practical questions about mark size and placement will get answered.
Five things to do this week
Just over three weeks in, the Commission's guidelines and FAQ have not moved since the rules applied. Checked against the Commission's own pages again on the morning of 26 August. The list below is current.
- Split the image library by whether a synthetic human is in the frame. That single cut does most of the work.
- Mark the deep fakes, sized against the smallest place the asset will really be seen, which for beauty is a phone-sized social grid. A mark that dies in the grid has been easily overlooked, which is the guidelines' own test for failure.
- Decide who the deployer is on every live campaign, write it down, and assume it is shared until a contract says otherwise. Push the same wording down to distributors and retailers who will republish the asset.
- Check the archive, not just the new work. Content generated before 2 August needs no retroactive labelling, and paragraph 154 keys that relief to when the image was generated, not to when it is published. The relief is narrower for AI-generated text, where it falls away for text published on or after 2 August to inform the public on a matter of public interest. Ordinary product copy is not caught by that.
- Date your AI literacy briefing. Article 4 has applied since 2 February 2025, and supervision began in early August 2026, with the Commission's own AI literacy questions and answers giving 3 August. The wording was softened on 27 July by the Omnibus, from ensuring literacy to taking measures to support it, but the duty stands. A dated internal briefing with an attendance record answers it.
The clock most brands have missed
Providers of generative systems already on the market before 2 August have until 2 December 2026 to meet the machine-readable marking duty, under the new Article 111(4). So your tools may not be marking their output yet, even though your own visible duty started on 2 August. That gap is the provider's to close, and it does not excuse your label. One rider from paragraph 153: where a system is partly interactive and partly generative, the extension covers only the Article 50(2) marking. The Article 50(1) duty to tell a person they are talking to a machine was due on 2 August.
And the bigger risk may not be the AI Act at all. An image that escapes Article 50 can still be an unfair commercial practice under Directive 2005/29/EC, and beauty carries its own claims regime under Article 20 of Regulation (EC) No 1223/2009, with the operative criteria in Regulation (EU) No 655/2013. For a before-and-after or a results shot, that is the harder test, and it has been in force for years.
Sources: Regulation (EU) 2024/1689, Articles 3(60), 50, 99 and 111. Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026. Commission guidelines on the implementation of the transparency obligations under Article 50, C(2026) 5054 final, 20 July 2026. Code of Practice on Transparency of AI-generated Content, final, 10 June 2026. European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content, 31 July 2026. European Commission, AI literacy questions and answers, updated 27 July 2026. Regulation (EC) No 1223/2009, Article 20, and Regulation (EU) No 655/2013.
This article is general information about the regulation and is not legal advice.