{"id":11180,"date":"2026-05-18T16:27:53","date_gmt":"2026-05-18T15:27:53","guid":{"rendered":"https:\/\/lawwwing.com\/?p=11180"},"modified":"2026-05-18T16:27:53","modified_gmt":"2026-05-18T15:27:53","slug":"eu-ai-act-for-ecommerce-what-you-need-to-do-and-what-happens-with-your-deepfake-images","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/eu-ai-act-for-ecommerce-what-you-need-to-do-and-what-happens-with-your-deepfake-images\/","title":{"rendered":"EU AI Act for ecommerce: what you need to do (and what happens with your deepfake images)"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><strong>European AI law already requires online stores to label deepfake images.<\/strong> Virtual models that look like real people, AI-generated faces, lifestyle scenes with synthetic characters that could pass for authentic photographs... if you are using any of these in your store without disclosing it, you are already breaking the EU AI Act. This guide explains exactly what the regulation requires, which images it applies to, and how to comply without the headache.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Table of contents<\/h5>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"#what-is-the-ai-act\">What is the EU AI Act and why does it affect your online store<\/a><\/li>\n\n\n\n<li><a href=\"#ai-tools-ecommerce\">Which AI tools do ecommerce businesses use: the list that might surprise you<\/a><\/li>\n\n\n\n<li><a href=\"#risk-classification\">Risk classification: where does your store fall<\/a><\/li>\n\n\n\n<li><a href=\"#article-50\">Article 50 and the obligation to label deepfakes: what almost nobody is doing<\/a><\/li>\n\n\n\n<li><a href=\"#other-obligations\">Other AI Act obligations for online stores<\/a><\/li>\n\n\n\n<li><a href=\"#key-dates\">Key dates for ecommerce businesses<\/a><\/li>\n\n\n\n<li><a href=\"#penalties\">Penalties: how much non-compliance can cost you<\/a><\/li>\n\n\n\n<li><a href=\"#checklist\">AI Act compliance checklist for ecommerce<\/a><\/li>\n\n\n\n<li><a href=\"#ai-sentinel\">AI Sentinel: automatically detect which images on your site are deepfakes and label them<\/a><\/li>\n\n\n\n<li><a href=\"#faq\">Frequently asked questions<\/a><\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is the EU AI Act and why does it affect your online store<\/h2>\n\n\n\n<p> <\/p>\n\n\n\n<p>The <strong>EU Artificial Intelligence Act<\/strong> (Regulation EU 2024\/1689), commonly known as the <strong>AI Act<\/strong>, is the world's first comprehensive AI law. It entered into force in August 2024 and applies in stages: some obligations are already in effect, with full enforcement reaching most businesses on <strong>2 August 2026<\/strong>.<\/p>\n\n\n\n<p>Do not mistake \"phased application\" for \"I can wait.\" The <strong>transparency obligations under Article 50<\/strong> (which include the labelling of AI-generated content) <strong>are already in force<\/strong>. And that is where most online stores have a compliance problem without realising it.<\/p>\n\n\n\n<p>Spain's AI supervisory agency (AESIA) has already opened 23 preliminary investigations. The Spanish data protection authority (AEPD) has increased AI-related investigations by <strong>340% compared to the previous year<\/strong>. Across the EU, the ecommerce sector has seen <strong>330% more in digital compliance fines<\/strong> over the past year alone.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why is ecommerce particularly exposed?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>Because ecommerce has adopted AI faster than almost any other sector, and has done so without thinking too hard about the legal implications. Today, a significant share of the images on online stores have passed through some form of generative AI: virtual fashion models that look like real people, AI-generated lifestyle photography, product images where the human context is entirely synthetic...<\/p>\n\n\n\n<p>When those images could pass for authentic photographs of real people, they fall within the definition of a deepfake under the AI Act and must be labelled. Today, almost none of them are.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Which AI tools do ecommerce businesses use <\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>Before you can address your obligations, you need to know which AI systems you are actually using. Many online stores use AI without being fully aware of it. Here is the most common picture:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Tool<\/th><th>Typical ecommerce use<\/th><th>Does it create or alter images of people?<\/th><\/tr><\/thead><tbody><tr><td>Midjourney, DALL-E, Firefly (to create realistic people or scenes)<\/td><td>Virtual fashion models, AI lifestyle photography<\/td><td><strong>Yes, if the result could be mistaken for a real photo<\/strong> (deepfake)<\/td><\/tr><tr><td>AI virtual fashion models (Botika, Ablo)<\/td><td>Showing garments on AI-generated people<\/td><td><strong>Yes<\/strong> (deepfake: synthetic person who looks real)<\/td><\/tr><tr><td>AI face or body alteration tools<\/td><td>Modifying a real person's appearance in a photo<\/td><td><strong>Yes<\/strong> (deepfake: manipulation of a real person's likeness)<\/td><\/tr><tr><td>Midjourney, DALL-E, Firefly (for objects or abstract content)<\/td><td>Product shots without people, abstract banners<\/td><td>No (not a deepfake)<\/td><\/tr><tr><td>Canva AI, Adobe Generative Fill (background or object editing)<\/td><td>Removing backgrounds, adding non-human elements<\/td><td>No (not a deepfake)<\/td><\/tr><tr><td>AI image upscaling tools<\/td><td>Improving resolution of product photos<\/td><td>No (not a deepfake)<\/td><\/tr><tr><td>AI-powered customer service chatbots<\/td><td>Support, FAQs, recommendations<\/td><td>No, but disclosure to users is required (Art. 50.1)<\/td><\/tr><tr><td>AI product recommendation engines<\/td><td>\"You might also like\"<\/td><td>No, but transparency is required<\/td><\/tr><tr><td>Dynamic or personalised pricing<\/td><td>Real-time price adjustments<\/td><td>No, but transparency is required when prices are personalised<\/td><\/tr><tr><td>AI fraud detection<\/td><td>Automatic blocking of suspicious transactions<\/td><td>No, but may qualify as high risk<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>The key question is whether the image depicts a person (real or synthetic) in a way that could be mistaken for an authentic photograph. A product-only shot, a typographic banner, or an AI-generated background are not deepfakes. A virtual model who looks like a real person wearing your clothes is.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Risk classification: where does your store fall<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>The AI Act organises AI systems into four risk levels. Most ecommerce businesses operate at the <strong>limited risk<\/strong> and <strong>minimal risk<\/strong> levels, but that does not mean they have no obligations. It means their obligations are primarily around <strong>transparency<\/strong>.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Unacceptable risk: prohibited since February 2025<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>Systems that are entirely banned in the EU. For ecommerce, the most relevant cases are using AI to psychologically manipulate users (subliminal techniques to push a purchase), exploiting the vulnerabilities of groups such as minors or elderly people, or real-time facial recognition in public spaces without consent. If any of your tools do this, they must be removed immediately.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">High risk: full obligations from August 2026<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>For ecommerce, this primarily affects businesses that offer instalment payments or buy-now-pay-later with <strong>AI-based credit scoring<\/strong>, or <strong>fraud detection systems<\/strong> that automatically block or penalise users. These require technical documentation, human oversight, activity logging, and impact assessments.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Limited risk: transparency obligations (already in force)<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>This is where most ecommerce sits. It covers chatbots, recommendation engines, personalised pricing, and, critically, <strong>all visual content generated or manipulated by AI that could constitute a deepfake<\/strong>. The Article 50 transparency obligations apply at this level and are already in force.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Minimal risk: no specific obligations<\/h3>\n\n\n\n<p>Spam filters, basic catalogue search without profiling, spell-checkers. No formal obligations.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Article 50 and the obligation to label deepfakes: what almost nobody is doing<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>This is the provision that affects ecommerce businesses most right now, and the one that is being most widely ignored.<\/p>\n\n\n\n<p><strong>Article 50 of the AI Act<\/strong> sets out several transparency obligations. The provision with the most direct impact on ecommerce businesses as deployers of AI is <strong>paragraph 4<\/strong>: it requires disclosure whenever content constitutes a <strong>deepfake<\/strong>, meaning images, video, or audio generated or manipulated by AI that depicts people, places, or events in a way that appears authentic but is not.<\/p>\n\n\n\n<p>The obligation does not apply to all AI-generated or edited content. It applies specifically to content that could mislead viewers about the authenticity of what is being depicted. The central question is whether the content could pass for a real photograph or recording.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What counts as a deepfake in ecommerce?<\/h3>\n\n\n\n<p>In the context of an online store, the most common cases are the following.<\/p>\n\n\n\n<p><strong>AI-generated virtual fashion models.<\/strong> If you use tools like Botika or Ablo to show your garments on synthetic people who look like real human beings, those images are deepfakes under the AI Act. The consumer is looking at a \"person\" who does not exist, with an appearance designed to look like an authentic photograph.<\/p>\n\n\n\n<p><strong>AI-generated people in product or lifestyle imagery.<\/strong> If you use Midjourney, DALL-E, or similar tools to create lifestyle photography in which people appear to be using or interacting with your product, and those people could be mistaken for real individuals in a real situation, those images are deepfakes.<\/p>\n\n\n\n<p><strong>Alteration of a real person's appearance.<\/strong> If you use AI to modify the face, body, or appearance of a real person in an image (for example, making a model look younger or changing their features with Generative Fill), that manipulated image is a deepfake.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does NOT count as a deepfake?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>It is just as important to know what falls outside this obligation. A product-only image without people, generated or retouched with AI, is not a deepfake. An AI-created typographic banner is not a deepfake. An AI-generated background behind a real product is not a deepfake. Removing a background with AI, or improving resolution with upscaling, is not a deepfake.<\/p>\n\n\n\n<p>The line is the deceptive representation of people: if there is no person (real or photorealistic synthetic) in the image, the Article 50.4 obligation is not triggered.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What about watermarking?<\/h3>\n\n\n\n<p>The AI Act provides for the use of technical marking mechanisms (watermarking) to identify deepfake content, particularly through <strong>metadata<\/strong>. This means compliance is not satisfied simply by adding a small \"AI-generated\" text somewhere on the page. The image file itself must be identifiable as AI-generated or manipulated through its metadata, following standards such as C2PA (Coalition for Content Provenance and Authenticity).<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The real problem: you do not know which images on your store are deepfakes<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>This is the core obstacle for most ecommerce businesses. If you have hundreds or thousands of images in your store (some supplied by manufacturers, some by agencies, some created in-house), <strong>there is no manual way to know which ones contain AI-generated or AI-altered people<\/strong>. And without knowing, you cannot label them.<\/p>\n\n\n\n<p>That is exactly the problem AI Sentinel by Lawwwing solves.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Other AI Act obligations for online stores<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>Beyond deepfake labelling, the AI Act imposes further obligations that every ecommerce business should be aware of.<\/p>\n\n\n\n<p><strong>Chatbot transparency.<\/strong> If you have an AI-powered virtual assistant or customer service chatbot, you must inform users that they are speaking with an AI and not a human being. This obligation has been in force since February 2025. A clear, visible notice at the start of the conversation is sufficient, but it must be unambiguous.<\/p>\n\n\n\n<p><strong>Transparency in recommendations and personalised pricing.<\/strong> If your store displays AI-powered product recommendations or charges different prices based on user profiles, you must disclose this. Users have the right to know when a decision affecting them has been made or influenced by an automated system.<\/p>\n\n\n\n<p><strong>Updated privacy policy.<\/strong> Your privacy policy must reflect every AI system that processes personal data: what data is used, for what purpose, whether automated decisions are involved, and how users can exercise their rights in relation to those decisions.<\/p>\n\n\n\n<p><strong>AI literacy (Art. 4).<\/strong> Article 4 of the AI Act requires businesses to ensure that employees working with AI systems have the minimum knowledge and skills needed to use them safely and responsibly. This obligation has been in force since February 2025.<\/p>\n\n\n\n<p><strong>Supplier contract review.<\/strong> If you use third-party AI tools (AI-powered email marketing platforms, smart advertising tools, AI plugins for Shopify...), you must review your contracts to verify that the provider complies with the AI Act. As a deployer, you have your own obligations that do not disappear simply because you sourced the tool from a third party.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key dates for ecommerce businesses<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Date<\/th><th>What comes into force<\/th><th>Already active?<\/th><\/tr><\/thead><tbody><tr><td><strong>1 August 2024<\/strong><\/td><td>EU Regulation 2024\/1689 enters into force<\/td><td>\u2705<\/td><\/tr><tr><td><strong>2 February 2025<\/strong><\/td><td>Prohibited practices (unacceptable risk) + AI Literacy (Art. 4) + Transparency obligations under <strong>Art. 50<\/strong> including deepfake labelling<\/td><td>\u2705 Already applies<\/td><\/tr><tr><td><strong>2 August 2025<\/strong><\/td><td>Obligations for general-purpose AI models (GPAI)<\/td><td>\u2705<\/td><\/tr><tr><td><strong>2 August 2026<\/strong><\/td><td>Full enforcement for high-risk AI systems (Annex III)<\/td><td>\u23f3 In 77 days<\/td><\/tr><tr><td><strong>Dec 2027 (possible)<\/strong><\/td><td>Potential extension for some high-risk systems via Digital Omnibus (pending approval)<\/td><td>\u2753 Not confirmed<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>The Article 50 deepfake labelling obligation is already in force.<\/strong> It is not a future requirement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Penalties: how much non-compliance can cost you<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Type of infringement<\/th><th>Maximum penalty<\/th><\/tr><\/thead><tbody><tr><td>Prohibited AI systems (unacceptable risk)<\/td><td><strong>\u20ac35 million<\/strong> or <strong>7% of global annual turnover<\/strong><\/td><\/tr><tr><td>Non-compliance with high-risk system requirements<\/td><td>\u20ac15 million or 3% of global turnover<\/td><\/tr><tr><td>Non-compliance with transparency obligations (Art. 50)<\/td><td>\u20ac7.5 million or 1% of global turnover<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Fines for breaching Article 50 (the provision covering deepfake labelling) can reach <strong>\u20ac7.5 million or 1% of global annual turnover<\/strong>. For a mid-sized store with \u20ac2 million in revenue, that is up to \u20ac20,000 in fines for failing to label images correctly.<\/p>\n\n\n\n<p>These penalties <strong>stack on top of GDPR fines<\/strong>. If the AI system also processes personal data (for example, profiling used to serve those images), you can face fines from both regulations for the same incident.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI Act compliance checklist for ecommerce<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>Transparency and labelling obligations (Art. 50), already in force<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>I have audited my store's images to identify which ones contain real or synthetic people generated or altered by AI that could be mistaken for authentic photographs<\/li>\n\n\n\n<li>Images that constitute deepfakes are labelled in a way that is clearly visible to users<\/li>\n\n\n\n<li>Labelling includes technical metadata (watermarking) where possible, following C2PA standards<\/li>\n\n\n\n<li>I have confirmed that images without people (product shots, backgrounds, abstract banners) do not require labelling under Art. 50.4 even if they were generated with AI<\/li>\n\n\n\n<li>My chatbot informs users at the start of the conversation that they are talking to an AI<\/li>\n\n\n\n<li>AI-generated product recommendations are identified as such<\/li>\n\n\n\n<li>If I apply AI-personalised pricing, users are informed<\/li>\n<\/ul>\n\n\n\n<p><strong>Privacy and data protection<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>My privacy policy reflects the use of AI and any automated decision-making<\/li>\n\n\n\n<li>I have carried out a DPIA for systems that process personal data using AI<\/li>\n\n\n\n<li>My forms include valid, up-to-date consent clauses<\/li>\n<\/ul>\n\n\n\n<p><strong>Team and compliance culture<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>I have trained my team on responsible AI use (AI Literacy, Art. 4, already in force)<\/li>\n\n\n\n<li>I have reviewed contracts with AI tool providers<\/li>\n\n\n\n<li>I have identified who is responsible for AI Act compliance in my business<\/li>\n<\/ul>\n\n\n\n<p><strong>For high-risk systems (if applicable: credit scoring, fraud detection)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>I have designated human supervisors for automated decisions<\/li>\n\n\n\n<li>I have carried out a Fundamental Rights Impact Assessment (FRIA)<\/li>\n\n\n\n<li>Systems have activity logs and technical documentation<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI Sentinel: automatically detect which images on your site are deepfakes and label them<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>Identifying which images in your store are deepfakes under the AI Act is harder than it sounds. Images arrive from manufacturers, agencies, freelance designers, stock libraries... and increasingly from generative AI tools that your own team uses day to day. Working out which ones contain synthetic people or AI-altered faces, and distinguishing them from images that simply have a retouched background or improved resolution, is not something that can be done manually at scale.<\/p>\n\n\n\n<p><strong>AI Sentinel by Lawwwing solves exactly that.<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How AI Sentinel works<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>AI Sentinel scans every image on your website and analyses, one by one, whether they contain people generated or manipulated by AI that could constitute a deepfake under Article 50.4 of the AI Act. The output is a clear report: which images require labelling, which do not, and how to proceed to document your compliance.<\/p>\n\n\n\n<p>With that information, you can act: label only what the law actually requires you to label, and stop worrying about the rest.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why this is especially critical for ecommerce<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>In fashion, beauty, and lifestyle retail, the use of AI-generated virtual models has exploded. They cost less than a photo shoot, are available instantly, and can be adapted to any garment or aesthetic. But they represent exactly the kind of content European legislators want identified as artificial: people who look real but are not, in situations designed to appear like authentic photographs.<\/p>\n\n\n\n<p>Article 50.4 exists precisely so that consumers know when what they are looking at is an artificial representation. In ecommerce, where images directly shape purchasing decisions and product expectations, that transparency also carries weight in terms of <strong>consumer rights<\/strong>.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">AI Sentinel fits into what you already have with Lawwwing<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>If you already use Lawwwing for GDPR compliance, cookie management, and legal texts for your store, AI Sentinel integrates into the same ecosystem. One single dashboard to manage your store's complete legal compliance: privacy, cookies, consent, and now AI content labelling as well.<\/p>\n\n\n\n<p>Compatible with WordPress, WooCommerce, Shopify, PrestaShop, Magento, Wix, and every other platform Lawwwing already supports.<\/p>\n\n\n\n<p><strong>Want to know how many images on your site are already in breach of Art. 50 of the AI Act?<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/app.lawwwing.com\/en\/signup\/\">Scan your store with AI Sentinel<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently asked questions about AI regulation and image labelling in ecommerce<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I have to label every image I edit with AI, or only some of them?<\/h3>\n\n\n\n<p>The obligation under Art. 50.4 of the AI Act for deployers (which is what ecommerce businesses are) applies specifically to <strong>deepfakes<\/strong>: content generated or manipulated by AI that depicts people, places, or events in a way that appears authentic but is not. It does not apply to all AI content, only to content that could mislead viewers about its authenticity.<\/p>\n\n\n\n<p>In practice: an AI-generated product photo with no people is not a deepfake. A virtual model generated with AI who looks like a real person wearing your clothes is. Removing a background with AI is not a deepfake. Altering a real person's face in an image with AI is.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What if the images were supplied by my manufacturer or agency and I do not know whether they used AI?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>You are responsible for the content you publish in your store. If you cannot demonstrate that an image was not generated or altered with AI, the risk sits with you. That is precisely why automated auditing with AI Sentinel matters: it tells you with certainty which images in your catalogue require labelling, regardless of where they came from.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is adding \"AI-generated\" text enough, or does something more technical need to happen?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>The AI Act provides for both visible notices to users and technical marking mechanisms (metadata watermarking). For basic compliance, a clear and visible disclosure next to the image or on the product page is the starting point. For full compliance, the European Commission is developing technical standards based on initiatives like C2PA that will require marking within the image file's own metadata. AI Sentinel helps you identify which images need that treatment.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does the AI Act apply to ecommerce businesses of all sizes, including small stores?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>Yes. The AI Act applies to any business that deploys AI systems or publishes AI content directed at users in the EU, regardless of size. Fines do have a proportional calculation for SMEs (whichever is lower between the fixed amount and the percentage of turnover), but the compliance obligations are the same. A small store with unlabelled AI-generated images is just as non-compliant as a large multinational.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is the Art. 50 labelling obligation a future requirement or is it already in force?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>It is already in force.<\/strong> The transparency obligations under Article 50, including the labelling of content generated or significantly manipulated by AI, came into effect on <strong>2 February 2025<\/strong>. This is not a future deadline. If you have unlabelled deepfake images in your store, you are already non-compliant.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is the difference between the AI Act and the GDPR for an ecommerce business?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>They are complementary regulations that apply simultaneously. The <strong>GDPR<\/strong> governs how your customers' personal data is processed (consent, purpose, access rights...). The <strong>AI Act<\/strong> governs how AI systems are used and communicated (risk classification, transparency, documentation, content labelling). You can be fully GDPR-compliant and still breach the AI Act by failing to label your deepfake images, and vice versa. Fines from both can accumulate.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is AI Sentinel and how does it work exactly?<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>AI Sentinel is Lawwwing's tool that scans every image on your website to detect which ones have been generated or significantly manipulated by artificial intelligence in a way that constitutes a deepfake under Art. 50.4 of the AI Act. It returns an image-by-image report so you can identify which ones require labelling and document your compliance. It is the fastest and most reliable way to audit the AI content in your online store without doing it manually.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: your store's imagery has to comply with the law too<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>The conversation around AI in ecommerce tends to focus on chatbots and recommendation algorithms. But there is a more immediate, more concrete, and far more overlooked obligation: <strong>the labelling of images that constitute deepfakes<\/strong>.<\/p>\n\n\n\n<p>It is already in force. It applies to any store that uses virtual models, AI-generated people, or images in which real people's appearances have been altered with generative AI. And non-compliance carries real penalties.<\/p>\n\n\n\n<p>The first step is knowing which images in your store are deepfakes under the AI Act. AI Sentinel by Lawwwing detects them for you, automatically, so you can act on real information rather than guesswork.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>Compliance starts with knowing what you have.<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/app.lawwwing.com\/en\/signup\/\">Analyse your website with AI Sentinel<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><em>Article last updated May 2026. This content is reviewed periodically to reflect regulatory changes under the EU Artificial Intelligence Act (Regulation EU 2024\/1689).<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>European AI law already requires online stores to label deepfake images. Virtual models that look like real people, AI-generated faces, lifestyle scenes with synthetic characters that could pass for authentic photographs... if you are using any of these in your store without disclosing it, you are already breaking the EU AI Act. This guide explains [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":11181,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[339,481,674],"tags":[],"class_list":["post-11180","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sin-categorizar-en","category-ecommerce-2","category-inteligencia-artificial-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11180","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=11180"}],"version-history":[{"count":1,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11180\/revisions"}],"predecessor-version":[{"id":11184,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/11180\/revisions\/11184"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/11181"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=11180"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=11180"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=11180"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}