AI & Compliance

EU AI Act: How to Label AI Images on Your Site (Free Plugin)

By Ibrahim Anjro · · 13 min read

Website showing an AI-generated image with a visible AI-generated disclosure label

Article 50 is live. Most guides confuse what the AI tool must do with what you must do. Here's the practical version — plus a free WordPress plugin.

If your website uses AI-generated images, a new EU rule now applies to you — and most of the advice being published about it is subtly wrong.

The confusion is understandable. The law splits responsibility between the company that built the AI tool and the business that published the image, and almost every guide blurs the two. The result is a lot of website owners believing they need to do things they can't do, while missing the one thing they actually must.

This guide fixes that. Here's what changed, whether it applies to you, exactly what you're responsible for, and how to label an entire media library in one click.

A note before we start: this is practical guidance from people who publish a lot of AI imagery, not legal advice. For a binding answer on your specific situation, talk to a qualified lawyer.

TL;DR — the short version

  • Since2 August 2026, the transparency rules in Article 50 of the EU AI Act apply.

  • There are two different duties. The AI tool's maker must add invisible, machine-readable marks. You, the business publishing the image, must add a visible label— but only when the image counts as a"deepfake."

  • Not every AI image is a deepfake. A realistic-looking photo of a plausible person, place, object or event likely is. Something clearly fantastical isn't.

  • Penalties for getting transparency wrong run to €15 million or 3% of worldwide annual turnover, whichever is higher.

  • The practical fix is three steps: inventory your AI images → apply a visible label → document what you did.

  • On WordPress, KI-Transparenz-EU does the labelling step in bulk — select the images, click once, and they're publicly labelled. It's free.

What changed on 2 August 2026

The EU AI Act is being phased in over several years.2 August 2026was the date the transparency obligations in Article 50became applicable.

Article 50 covers four situations: people talking to chatbots, AI-generated content being marked as such, emotion recognition and biometric categorisation, and deepfakes plus AI-generated text on matters of public interest. For most website owners, only the AI-image and chatbot parts matter.

Two points people routinely miss:

It isn't only for EU companies. The AI Act reaches providers and deployers who place AI systems on the EU market or whose AI outputs are used inside the EU. A US or UK business whose website serves European visitors is squarely in scope.

There's no grace period for your side of the duty. A limited extension exists — under the AI Omnibus agreement from May 2026, generative AI systems already on the market before 2 August 2026 have until2 December 2026to meet the machine-readable marking requirement. But that extension is for the AI system providers, not for you. The visible-disclosure duty on businesses publishing content applies now.

Does this actually apply to you?

Three questions, in order. If you answer "no" to the second, you can stop.

Provider or deployer — the distinction everyone gets wrong

This is the crux of the whole topic.

A provider is whoever develops and places the AI system on the market — OpenAI, Adobe with Firefly, Midjourney, Google, Stability. Under Article 50(2), providers must ensure their generated output is marked in a machine-readable format and detectable as artificially generated. That means invisible watermarks and signed provenance metadata baked in at generation time, and the law asks that these solutions be effective, interoperable, robust and reliable as far as is technically feasible.

A deployer is whoever uses the AI system — you, when you generate an image and publish it on your website. Under Article 50(4), deployers who use AI to generate or manipulate image, audio or video content that constitutes a deepfake must disclose that the content has been artificially generated or manipulated.

Why this matters practically: you cannot fulfil the provider's duty, and you don't need to. You can't retroactively inject cryptographic watermarks into someone else's model output. If a guide is telling you that your business must "watermark your AI images machine-readably," it has confused the two roles.

Your job is the human-facing label. That's it — and that part is entirely within your control.

Is your AI image a "deepfake"? The actual test

"Deepfake" sounds like it means fake celebrities and political hoaxes. Under the AI Act it's much broader, and this trips people up.

The definition covers AI-generated or manipulated image, audio or video content that resembles existing or realistically plausible persons, objects, places, entities or events, and that would falsely appear to a person to be authentic or truthful.

Two things follow, and both surprise people:

Intent to deceive is not required. You don't have to be trying to fool anyone. If the image looks real and depicts something plausible, it can qualify.

"Objects, places and events" are included, not just people. This is why the rule reaches ordinary commercial imagery — an AI-generated photo of a hotel room, a product on a table, an office, or a plate of food can meet the definition even though no person appears in it.

What falls outside it:

  • Clearly fantastical or physically impossible content— dragons, people flying unaided, obviously surreal scenes. Nobody would take it as authentic, so it isn't a deepfake.

  • Obvious illustration and stylised graphics— cartoons, diagrams, abstract art, plainly artificial 3D renders.

  • Content in an evidently artistic, creative, satirical or fictional context is treated more lightly, though transparency is still expected in an appropriate manner.

A useful working test: would a reasonable visitor, glancing at this image, assume a camera took it? If yes, treat it as in scope. If it's obviously drawn, rendered or impossible, it very likely isn't.

When you're not covered at all

You're outside Article 50's image rules if you don't publish AI-generated or AI-manipulated visual content — genuine photography, stock photos shot by humans, and your own illustrations don't trigger it. Routine editing also doesn't convert a real photo into a deepfake: the Act contemplates standard editing that doesn't substantially alter the reality of the underlying content. Cropping, colour grading and retouching a real photograph of your real premises is not the target. Using generative fill to add a building that was never there is a different matter.

What the law actually requires

Your duty: a visible, understandable disclosure

For images caught by the deepfake definition, the disclosure has to be perceivable by a human without needing a detection tool. In practice, that means a visible label — a caption, badge, overlay or clearly associated note — presented at the point where someone encounters the image.

Three practical qualities to aim for:

  1. Visible where the image is. A blanket line buried in your privacy policy doesn't do it. The disclosure should travel with the image.

  2. Plain language."AI-generated" or "Created with AI" is understood; a cryptic icon is not.

  3. Present on first encounter. Not behind a hover state, a click, or three scrolls down.

The provider's duty: machine-readable marking

For completeness — this is the part handled upstream. Providers embed machine-readable signals, most commonly using the C2PA standard: a cryptographically signed record of how a file was created and edited, embedded in its metadata. It's an open standard backed by a large industry coalition including Adobe, Microsoft, Google, the BBC and AP.

Worth knowing about its limits: C2PA metadata is fragile. Screenshot an image, re-upload it to a social platform, or convert the format, and the provenance data is usually stripped. This is precisely why the human-readable label exists as a separate requirement, and why the Commission's Code of Practice on Transparency of AI-generated Content describes a layered approach — metadata plus watermarking plus a visible label — rather than relying on any single mechanism.

One more duty worth knowing: AI-generated text

If you publish AI-generated or AI-manipulated text to inform the public on matters of public interest, that also has to be disclosed — unless a human took editorial responsibility and reviewed it, in which case you should be able to identify who that was. Marketing copy about your own products isn't the target; an AI-written news or current-affairs piece is. If you run an automated blog on public-interest topics, look at this properly.

What happens if you ignore it

Breaches of the Article 50 transparency obligations sit in a penalty tier of up to €15 million or 3% of total worldwide annual turnover, whichever is higher (see Article 99). The Act explicitly says proportionality should be considered for SMEs and small mid-caps, so a small business isn't facing a headline fine — but "small" is not "exempt."

Enforcement runs through national market surveillance authorities in each member state. In practical terms, the realistic near-term risk for most businesses isn't a spontaneous regulator audit — it's a complaint, from a competitor, a customer or an activist, about an unlabelled image that's been sitting on your site in plain view.

That's the honest risk picture: low probability of proactive enforcement, but a cheap and permanent fix available. Which makes it an easy decision.

How to label your AI images: four steps

Step 1 — Inventory every AI image you've published

You can't label what you haven't found. Work through:

  • Website pages — hero images, backgrounds, team and premises photos, section graphics

  • Blog post featured images and in-body illustrations

  • Product and menu imagery

  • Landing pages and campaign microsites

  • Anything in your CMS media library published in the last couple of years

For each, record: where it's used, whether it's AI-generated or AI-modified, which tool made it, and roughly when. If your team has generated images ad hoc, expect to find more than you think.

Shortcut: filenames and EXIF "Software" fields often still name the generator (DALL·E, Firefly, Midjourney, Stable Diffusion), and files that came from a C2PA-aware tool may still carry provenance metadata. That gets you most of the way through an audit fast.

Step 2 — Decide what your label looks like

Settle this once, then apply it everywhere:

  • Wording."AI-generated" is the clearest. "Created with AI" and "AI-generated image" are equally fine. Pick one and be consistent.

  • Placement. A caption directly beneath the image, or a small badge in a corner of it. Both work; captions are gentler on design.

  • Scope. Label the images that meet the deepfake test. Labelling everything is permitted and simpler to administer — just don't label real photography as AI, which is its own accuracy problem.

Step 3 — Apply the labels at scale

This is where most projects stall. Labelling forty images by hand across a CMS is a bad afternoon; four hundred is a project nobody starts. The tooling section below deals with this.

Step 4 — Write down what you did

Keep a short internal record: the date you audited, your labelling rule, which images were classified as in scope, and who signed off. It takes ten minutes and it's the difference between "we take this seriously, here's our process" and "we hadn't thought about it" if anyone ever asks.

Doing it on WordPress: KI-Transparenz-EU

We publish a lot of AI imagery ourselves, so we hit the step-3 problem directly and built a tool for it. It's free.

Plugin status — updated 7 August 2026. v1.0 is finished and free to download today. We've also submitted it to the official WordPress.org plugin directory; review usually takes a few weeks, and we'll update this page the day it's approved.

What it does

KI-Transparenz-EU adds bulk AI labelling to your existing WordPress media library — images and videos:

  • Select many images at once— filter your library, select the AI-generated ones

  • One click to label them— the disclosure is applied and shown publicly wherever those images appear

  • Works on what you've already published— no need to re-upload or re-create anything

  • Free, no account required, no lock-in— deactivate it and your site is unchanged

The distinction that matters: existing tools mostly make you flag images one file at a time. If you've got a library built up over two years, that's the whole problem. This is built to label four hundred images in about the time it takes to label four.

What it does — and what it doesn't

Being straight about the limits, because you're reading this for compliance reasons:

  • It applies the visible, human-readable disclosure— the deployer duty under Article 50(4).

  • It does not add cryptographic watermarks to image pixels. That's the AI provider's responsibility and isn't something a publishing plugin can do.

  • It does not decide for you which images are legally in scope. It gives you the mechanism; the classification call is yours (see the test above).

  • No plugin can make you "compliant"— compliance is a process, not a checkbox. This handles the labelling part of it well.

Install it

  1. Download the ZIP: https://github.com/IbramDawwaGmbH/KI-Transparenz-EU— source is public on GitHub if you want to read it first

  2. In WordPress: Plugins → Add New → Upload Plugin → Activate

  3. Go to Media, select your AI images, and apply the label

Prefer to install from the official directory? We'll update this post with the official link the day it's approved — you can also follow the WordPress.org developer profile. The Shopify and Wix versions are in development.

Not on WordPress?

The requirement is the same; only the mechanism changes.

  • Shopify / WooCommerce / other ecommerce— most themes let you add a caption field or an image overlay. Product imagery generated or heavily modified with AI is one of the clearest in-scope cases, so start there.

  • Webflow, Squarespace, Wix— add a caption element beneath AI images, or a small persistent badge in your image component so it's applied by default.

  • Custom sites— handle it at the component level: add anisAIGeneratedflag to your image data model and render the label from the component. Do it once, and every future image inherits it.

  • Social media— most major platforms now have their own AI-content declaration toggle. Use it; your website label doesn't travel with a re-uploaded file.

Five mistakes to avoid

1. Assuming you must watermark machine-readably. You can't, and you don't have to. That's the provider's duty. Your duty is the visible label.

2. Assuming every AI image needs a label. Obviously fantastical or clearly illustrative images generally fall outside the deepfake definition. Apply the test rather than blanket-labelling out of fear — though blanket-labelling is permitted if you prefer the simplicity.

3. Hiding the disclosure in your terms page. The label needs to be perceivable where the person meets the image, without a detection tool.

4. Thinking it doesn't apply because you're not in the EU. If your output is used in the EU, you're in scope.

5. Labelling and then forgetting. New AI images get published every week. Make the label part of your publishing workflow, not a one-off cleanup.

Frequently asked questions

Does the EU AI Act require me to label AI-generated images on my website? If the image meets the Act's "deepfake" definition — AI-generated or manipulated content resembling a realistically plausible person, object, place or event that could appear authentic — then yes, as a deployer you must disclose that it was artificially generated. The disclosure must be perceivable by a person without a detection tool. Obviously fantastical or clearly illustrative images generally aren't covered.

When did this start applying?2 August 2026. A separate extension to 2 December 2026 applies to machine-readable marking for generative AI systems that were already on the market before that date — but that concerns the AI providers, not businesses publishing images.

Do I need to watermark my AI images? No. Machine-readable marking is the obligation of the provider of the AI system that generated the content. As the business publishing the image, your obligation is the visible, human-readable disclosure.

Is an AI-generated product photo a deepfake? It can be. The definition covers realistically plausible objects and places, not just people, and intent to deceive isn't required. A photorealistic AI product or premises image that a visitor would assume was photographed generally falls in scope.

What are the penalties? Breaches of Article 50's transparency obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, with proportionality considered for SMEs. Enforcement is by national market surveillance authorities.

Does this apply to non-EU businesses? Yes, if your AI system's output is used in the EU. Serving European visitors is enough to bring you into scope.

Do I have to label AI-written text too? Only if it's published to inform the public on matters of public interest, and no human took editorial responsibility for it. Ordinary marketing copy isn't the target.

Does a plugin make me compliant? No tool can. A plugin applies the visible labels reliably and at scale, which is the mechanical part. Deciding which images are in scope, and keeping the practice up as you publish, is the rest of it.


Sources: Article 50, EU AI Act · European Commission FAQ on Article 50 transparency obligations · Commission guidelines on transparency of AI-generated content · Code of Practice on Transparency of AI-generated Content · Article 99, penalties · C2PA. Last reviewed 7 August 2026.

Written by

Ibrahim Anjro

Founder & Business Developer

+10 years of exp in Business Development