Export the last thirty creatives you ran in any EU market and sort them into two piles. Pile one: anything showing a person, place or object a viewer could reasonably believe is real. Pile two: everything else. Pile one is the only stack Europe's new AI labelling rule cares about. Generated any of it? Then some of those ads now have to say so out loud. Pile two, which for most e-commerce accounts is the bigger stack, is the noise you have been told to worry about and do not need to.
Compare that against the advice going round since the start of the month. Label everything, budget a compliance review, fines with seven zeros. Two weeks of it and the output is disclosure badges on stock-lit packshots no rule has ever touched, while the one category actually caught by the text ships unlabelled daily. Sorting thirty files by hand beats all of it.
What the rule actually asks of you
The law doing this is the EU AI Act, and its transparency rules switched on August 2. Two passages in it touch your work, they land on different people, and separating those two is most of the job. The one pointed at you is Article 50, paragraph 4. In plain terms it says this: if AI made or altered the picture, audio or video in your ad, and the result looks like something real, you have to tell people it is artificial. You are what the Act calls the deployer, meaning whoever actually runs the ad. Everything then hangs on one word inside its definition of a deepfake, content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic or truthful. Existing. Read it twice. That is the whole test, and it is narrower than the headlines.
Paragraph 2 of the same article is not about you at all. It tells the companies that build the generation tools to stamp an invisible tag inside every file they produce, so software can tell later that a machine made it. Nothing visible on the picture, and not your job. A later amendment package, the Digital Omnibus, gave that paragraph a transitional window for tools already on the market before August 2, and the law firms cannot agree where it ends, some writing December 2026, some February 2027. Either way the clock belongs to whoever built your generator.

The line that decides it for e-commerce creative
Run the four things a product brand actually makes against that definition. A fully synthetic person who resembles nobody living, holding your product, in a studio that never existed. No real person. No real place. The argument is that this is not a deepfake, and it is a reading of the text rather than a ruling, so hold it loosely. Now a generated background dropping your actual product into a kitchen it was never photographed in. Your product exists. The image is built to read as authentic. That one is inside the definition and almost nobody has clocked it. An AI-cleaned version of a photo you shot yourself, colour corrected, a blemish taken out: the Act carves out assistive standard editing that does not substantially alter the input or its meaning, so that is fine. And a customer's face swapped onto another body, or a recognisable public figure appearing to endorse you. Squarely a deepfake, and a separate legal problem you already had. So on a normal AI UGC workflow the exposure is lumpy, not spread out. It sits in generated environments wrapped around real products, and almost nowhere else.
Which is why the sort splits unevenly by category. A furniture or homeware brand runs mostly product-in-room creative, so much of the library lands in pile one. An apparel brand shooting flat lays and synthetic models lands almost none there. Same tooling, same prompts, different exposure, decided by what you sell rather than how much AI you used.

The mark you did not put there is the one that labels you
Take one generated file and drop it into contentcredentials.org/verify before you do anything else. That page looks for a C2PA manifest, an industry provenance tag some generators write into the file, and if one is there it tells you what made the image and when. That is the same manifest Meta reads on upload to apply its own AI label, and the same one TikTok reads, having joined the C2PA steering committee in July and started auto-labelling anything arriving from another platform. Nobody asks you first, and no regulator is anywhere near this part of it.
Before you get an idea about stripping it: pulling the manifest out breaks the cryptographic signature chain, verification tools flag the break, and a broken signature reads worse than the label you were avoiding. Once a platform applies that label it is not yours to remove either. So the sequence runs: your tool satisfies its own obligation, the platform reads the mark, your ad ships wearing a label, and none of it consulted whatever you concluded about your own duty. Upload one creative to each platform and look at the live ad. Ten minutes, and it answers what no blog post can for your stack.
The icons are optional. The obligation is not.
The Commission put out three EU icons: a basic AI mark, one for fully AI-generated, one for partially AI-modified, each in four variations, black and white plus both at 50% transparency. Free, no attribution required. Their own user testing found they work better paired with a word than alone, which is useful if you are designing the disclosure.

Then the line half the write-ups skip, printed plainly on the Commission's page: using the icon does not establish compliance by itself. Optional icon, mandatory obligation, and the advertiser stays on the hook for the disclosure actually meeting the requirement. Placement rules if you use one: perceivable at first exposure, nothing overlaying it, embedded so it survives a reshare or a download.
What the fine actually says
Article 99 is the penalties article. For breaching the transparency rules it sets up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups it flips: the cap is the lower of the two. That flip is missing from most of the coverage, and on a brand doing eight figures it moves the number by an order of magnitude. All of which is a reading of the published text and the Commission's guidance, not legal advice from anyone qualified to give it. Real money going into EU markets? Twenty minutes of counsel beats the alternative.
The audit, one afternoon
Pull every creative live in an EU market and put four columns next to it: what the asset is, was the environment generated, does anything in frame exist in the real world, what you decided. Sort by the third column. Everything answering yes is your list, and on most accounts it is a fraction of what you feared.
Then pick one disclosure wording and one placement and use them on the whole list, without re-litigating each case. Consistency is the point: someone reviewing a hundred assets next year reads variation as a judgement call made asset by asset. Run each flagged file through the verifier as you go and note the manifest beside the decision, the same way you track any other signal your stack emits. A reasoned decision you can evidence beats a perfect one you cannot.
Do it while the pile is small, because it does not stay small. Every quarter your automated creative pipeline runs, the generated share climbs and a retroactive audit gets uglier. Sort thirty assets now instead of three thousand in March.
Go pull the EU-active creative, run one file through the verifier, make the two piles. One afternoon and it becomes a list with an end to it. Then keep provenance in mind when you pick tooling, because knowing what went into a creative matters more than it did last year. Try Coinis AI if you want that part of the pipeline in one place.
Isidora Matovic
Author
Social media enthusiast and a full time researcher. She takes digital presence very seriously and that is why you are always in touch in what is going on with us! Follow us for more posts like this.