AI-generated product imagery, virtual models, synthetic backgrounds and automated retouching are quickly becoming part of everyday e-commerce production. From 2 August 2026, important transparency requirements under the EU AI Act will become applicable.
For retailers, brands, studios and content-production partners, this does not mean AI content needs to stop. It means AI must be used with greater transparency, control and traceability.
The first important fact: most e-commerce AI is not “high-risk”
The AI Act uses a risk-based approach. Most AI applications used for image production, retouching, copywriting and creative workflows are expected to fall into the limited-risk or minimal-risk categories rather than the heavily regulated high-risk category.
However, generative AI is still subject to specific transparency requirements, particularly when it creates or materially alters images, video, audio or text.
Not every AI-assisted image needs a visible label
There is no blanket requirement to place a visible “AI-generated” label on every product image that has been touched by AI.
The Act distinguishes between different types of use:
- Standard editing or assistive changes that do not substantially alter the original content may be excluded from the AI-content marking requirement.
- Providers of generative AI systems must generally make generated or substantially manipulated outputs detectable in a machine-readable format.
- Businesses using AI must visibly disclose image, video or audio content when it qualifies as a deepfake: content that resembles a real person, object, place or event and could falsely appear authentic.
This distinction is important for e-commerce. Background removal, cropping or minor colour correction is not treated in the same way as generating a synthetic model, changing how a garment fits, creating an artificial lifestyle scene or generating a complete product video.
Whether visible disclosure is necessary will depend on what was generated, how substantially the source material was changed and how the final image is presented to the consumer.
Machine-readable information will become more important
Generative AI system providers will be responsible for making synthetic outputs detectable as AI-generated or manipulated, where technically feasible. This may include metadata, content credentials, watermarking or other provenance technologies.
For studios and e-commerce businesses, the practical consequence is that production and delivery workflows should be able to preserve this information where available.
Simply adding “AI” to a filename is not a complete compliance strategy. Businesses should be able to trace:
- which assets were created or materially changed using AI;
- which system and workflow were used;
- which source assets were involved;
- whether the output was reviewed by a person;
- who approved the final content;
- what was ultimately delivered or published.
Responsibility is shared across the production chain
The AI Act distinguishes between a provider, which develops or offers an AI system under its own name, and a deployer, which uses an AI system professionally under its authority.
An AI-platform provider, production studio, retailer and brand may therefore have different responsibilities. In some workflows, an organisation may even be both a provider and a deployer.
Contracts and production specifications should clarify who is responsible for:
- AI-content classification;
- technical marking and metadata;
- visible consumer disclosures;
- human quality control;
- record keeping;
- responding to compliance or audit requests.
The European Commission has also published a voluntary Code of Practice covering the marking and labelling of AI-generated content. The legal obligations remain applicable even when an organisation does not sign the code.
AI literacy already applies
Since February 2025, organisations using AI have been required to take measures to ensure that employees and contractors working with AI have an appropriate level of AI literacy.
This does not necessarily mean every employee needs a formal AI certificate. It does mean the people operating and reviewing AI systems should understand the relevant tools, limitations, risks and required controls.
For creative production teams, this includes recognising hallucinated details, inaccurate product representation, unwanted changes to logos or materials, bias in synthetic models and situations requiring escalation or human correction.
What businesses should do now
The most useful first step is to map where AI is already present in the content supply chain.
Review image generation, automated retouching, virtual models, video generation, translations, product descriptions, quality-control tools and internal workflow automation. Then determine whether each organisation is acting as a provider, deployer or service partner.
Businesses should also establish a clear policy for human review, asset traceability, metadata retention and consumer disclosure.
The Act does not replace existing requirements relating to copyright, privacy, advertising, consumer protection or accurate product representation. AI content must still show the product honestly and must not mislead customers.
Implementing EU disclosure icons
The European Commission has introduced specific visual icons to help consumers identify AI-generated or manipulated content. While it is ultimately the client’s responsibility to disclose this on their platforms, Bright River can support the implementation process by integrating these labels into production specifications. This ensures assets are clearly marked and compliant, making it easier for clients to manage transparency and build trust with their customers.
Our approach
At Bright River, we are preparing our AI-enabled workflows around four principles:
Traceability: recording when and how AI has been used.
Human oversight: maintaining quality control and approval before delivery.
Product accuracy: ensuring that AI does not materially misrepresent the product.
Transparency: supporting machine-readable provenance and client-specific disclosure requirements where applicable.
These 4 principles are used to generate json metadata for every AI image generated in our production workflows, which is stored securely in case of future audits or compliance verification, and to support customer requests for transparency regarding AI-generated or materially manipulated assets.
AI will continue to make e-commerce production faster, more flexible and more scalable. The EU AI Act does not change that direction. It does, however, make responsible implementation, documentation and production governance a formal part of using AI professionally.
Tommy Hulsbosch
Head of AI

