From 2 August 2026, your ecommerce business must disclose when an AI-generated image, video or audio looks real, and when a person is interacting with an AI system. This guide explains what to disclose, where to place it and which uses need to be redone.
A guide for Shopify and WooCommerce stores
This guide is designed to help you apply AI transparency obligations on the two ecommerce platforms most commonly used by our clients.
Shopify
WooCommerce
This document explains what the European AI regulation requires from 2 August 2026, what falls outside its scope and what to do at each point in an online store. It is not legal advice: for decisions involving potential penalties, you should have them reviewed by your legal adviser.
What changes for your store
From 2 August 2026, you must disclose when an AI-generated image, video or audio looks real enough that it could be mistaken for authentic, and when a person is speaking with an AI system.
In an online store, this is concentrated in just a few places: the product page, campaign images, the customer service chat and reviews. The rest of your AI use (describing products, translating, optimising and segmenting) does not require disclosure.
There is a second layer that often matters more than the first: consumer law. An image that makes a product look different from what arrives at a customer’s home is misleading advertising, whether it is labelled or not. And fake reviews are prohibited regardless of how they were written.
The one-sentence rule
If the image influences the purchase decision and does not faithfully represent what you are going to send, the problem is not solved by adding a label: the image must be changed.
The regulation’s four obligations, and who is responsible for each one
The most common mistake is to treat this as a single obligation. There are four, and each one falls on a different actor.
| Obligation | Who it applies to | What it means in practice |
|---|---|---|
| Make sure people know they are interacting with an AI system, unless this is obvious from the context | The system provider | You choose and configure the tool, so the welcome message is your responsibility. If you put your brand on a third-party system and present it as your own, you may be treated as a provider |
| Mark outputs in a machine-readable format | The provider of the generative tool | Creating it is not your obligation, but you should avoid destroying it: exporting or recompressing files can remove their provenance metadata |
| Disclose the use of emotion-recognition or biometric-categorisation systems | The deployer, meaning you | This affects tone or facial-expression analysis. Inferring emotions from employees or students has been directly prohibited since February 2025 |
| Disclose deepfakes and AI-generated text published on matters of public interest | The deployer, meaning you | This is the obligation that directly affects you |
The information must be provided clearly and distinctly, no later than the first time the content is shown, and it must be accessible.
What exactly is a deepfake?
The regulation defines it as image, audio or video content generated or manipulated with AI that resembles existing people, objects, places, entities or events and would appear authentic to the person viewing it.
It is worth reading that twice: it is not only about famous people. It also covers objects, places and events. A recreation of a real product, premises or situation falls within this definition. A clearly stylised illustration or an impossible scene does not.
Three exceptions that keep things simple
- Standard editing. Correcting colour, removing noise, increasing resolution, cropping or removing a background without changing the meaning does not trigger any obligation.
- Human review, for text only. If the text goes through editorial review or control and a person or company assumes responsibility for publication, no disclosure is required.
- Content published before 2 August 2026. You do not have to relabel content that has already been published. For text, the relevant date is the publication date.
How to decide: three questions, four outcomes
Question 1. Does the piece represent something or someone that exists, in a way that could make it appear authentic?
Question 2. Does a disclosure solve the problem, or is the problem that the piece makes a false claim?
Question 3. Is there an identifiable person who has genuinely reviewed the piece and takes responsibility for what was published?
| Outcome | What it means |
|---|---|
| No disclosure | Instrumental use of AI. Publish normally |
| Mandatory disclosure | The regulation requires it. Do not publish without it |
| Recommended disclosure | The regulation does not require it, but commercial or reputational risk makes it advisable |
| Redo | No label can correct the problem, because the problem is deception or a lack of rights |
How to write the disclosure and where to place it
The regulation requires the information to be clear, distinguishable and accessible, and available before people interpret what they see. That rules out most of the notices currently in circulation.
Does not comply: a line in the footer, a mention in the privacy policy or terms and conditions, text that appears for half a second in a video, a watermark hidden by the interface, or a notice that disappears when the piece is downloaded or shared.
Does comply: a notice on the piece itself, visible on first exposure, placed where nothing covers it, embedded in the content whenever possible, written in plain language and accompanied by a text alternative for screen readers.
Official EU icons
The European Commission provides three example variants on its official page about icons for labelling AI-generated content. Their use is optional and does not, by itself, demonstrate compliance with Article 50: what matters is that the notice is clear, visible and accessible.



The European Commission has published a set of free icons, available for use without attribution, in SVG and PNG. They are optional and work best when accompanied by text rather than used alone. There are three variants: basic, fully generated with AI and partially modified with AI. Using them does not, by itself, prove compliance.
Formulas that work
| Situation | Formula |
|---|---|
| Product or service image | “AI-generated image. Non-photographic recreation.” |
| Space, premises or facility | “AI-generated recreation. This is not a photograph of the premises.” |
| Video with a synthetic spokesperson | On-screen text in the first few seconds and persistent overlay: “Virtual spokesperson generated with AI.” |
| Audio or cloned voice | Spoken notice at the beginning: “Voice generated with AI with the person’s authorisation.” |
| Chat or assistant | First message: “I am [brand]’s virtual assistant. I respond using artificial intelligence. You can ask to speak to a person at any time.” |
| Unreviewed informational text | Heading, not footer: “AI-generated text. Published without editorial review.” |
| Social media | The platform’s native label and, in addition, a notice within the creative, because the native label is lost when the piece is reshared |
Surface by surface
Product detail page (PDP)
| Situation | What to do |
|---|---|
| AI-generated product photo that faithfully represents the real item (same material, colour, finish and proportions) | No disclosure required. We still recommend stating it in craft, food or premium-material stores, where the expectation of a real photograph is high |
| Product on a generated background or in a synthetic setting | No disclosure required if the product itself is not altered |
| Product retouched until it looks like something else (more shine, more volume, different texture, larger serving) | Redo it. It creates a risk of misleading advertising and returns |
| Generated human model wearing the garment | Disclosure recommended and, if the model resembles a real person, mandatory. Always add the garment’s actual measurements and the size worn by the model |
| Product video with a generated demonstration of a feature | Mandatory disclosure if it looks like a real recording of the product in use |
| Existing 3D product renders created before August 2026 | Content published before that date does not need to be relabelled |
| Product description, bullets and technical specification written with AI | No disclosure required. The information must still be accurate: composition, measurements, origin and warranties |
Category pages, home page and campaigns
| Situation | What to do |
|---|---|
| Banner or header with a generated scene and no identifiable product | No disclosure |
| Scene with synthetic “customers” using the product | Disclosure in the creative |
| Recreation of the physical store, workshop or warehouse | Mandatory disclosure: it is a real place represented without being the real place |
| Clearly fantastical piece (impossible world, illustration style) | No disclosure, or a minimal mention if there are hyper-realistic elements |
Reviews, ratings and customer content
| Situation | What to do |
|---|---|
| AI-generated reviews | Prohibited. It is an unfair practice, with or without disclosure |
| Automatic summary of real reviews on the product page | Notice: “Summary generated with AI from verified reviews” |
| Responses to reviews drafted with AI and reviewed before publication | No disclosure |
| Customer photos recreated or enhanced with AI | Disclosure and the person’s consent |
| Verification that the reviewer actually made a purchase | An increasingly common obligation under consumer law. Check what your review app does |
Chat, shopping assistant and after-sales
| Situation | What to do |
|---|---|
| AI customer-service chat | Mandatory disclosure in the first message, with an option to reach a person always available |
| Product or size recommendation assistant | Mandatory disclosure, plus a warning that the recommendation is indicative |
| WhatsApp bot for order tracking | Mandatory disclosure at the start of the conversation |
| Human-looking avatar in the chat | Mandatory, reinforced disclosure: the more human it looks, the clearer it must be that it is not human |
Email, automation and advertising
| Situation | What to do |
|---|---|
| Abandoned-cart, welcome or post-purchase emails written with AI | No disclosure |
| AI-generated product image included in the email | Apply the same criterion as for a product page |
| Social ads with generated creative | Disclosure within the creative, in addition to the platform’s native label |
| Price or offer personalisation using an algorithm | It does not fall under Article 50, but consumer-information obligations on personalised pricing still apply |
Where to implement it in practice
- Shopify. The notice can appear as text over the image, in a theme block below the gallery, in a reusable product metafield or in a rich-content block. Avoid placing it only in the long description: many people will not scroll that far.
- WooCommerce. Use a reusable block in the product template, a visible global attribute or text embedded in the image itself. Be careful with image-optimisation plugins that rewrite files.
- Both platforms. If the notice exists only in the theme, it disappears when the image is shared, downloaded or sent to a comparison service or product feed. For the highest-risk pieces, embed it in the image.
Four checks before publishing
- Does the image correspond to what the person who buys it will receive?
- Could someone seeing this piece think it is a real photograph of something real?
- Is the notice visible before the decision is made, and does it remain there if the image is shared?
- Is there an identified person who has reviewed and approved the piece?
How to put it into practice
| Step | Content | Who |
|---|---|---|
| 1. Inventory | List where AI is currently used in each channel: product pages, creative assets, chat, automations and third-party apps | Impulsa3 with your team |
| 2. Classification | Run each use through the three questions and keep only the cases that result in “disclose” or “redo” | Impulsa3 |
| 3. Quick fixes | Chat welcome message, human handoff and notices on the live pieces with the highest risk | Impulsa3 |
| 4. Templates | Disclosure formulas for each channel and a reusable block in the template | Impulsa3 |
| 5. Register | One row for each published piece: which tool was used, what AI did, which disclosure it carries and who approved it | Both |
| 6. Training | A short AI-literacy session for the team. It has been a legal obligation since February 2025, and it is worth being able to demonstrate that it was completed | Impulsa3 |
For the register, eight fields in a spreadsheet are enough. Piece and URL, publication date, tool and version, exactly what the AI did, the decision outcome, the literal disclosure text and where it appears, who reviewed and who approved it, and image or voice permissions when people are involved. Do not store unnecessary personal data or discarded variants.
Sources
Regulations and official documentation consulted on 1 August 2026.
- Regulation (EU) 2024/1689 (European AI Act), Article 50. Transparency obligations. Official text on the European Commission service: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI). Published in the Official Journal of the European Union on 24 July 2026 and in force since 27 July 2026. It postpones high-risk obligations and gives until 2 December 2026 for the technical marking of systems already on the market. It does not postpone Article 50. https://www.boe.es/buscar/doc.php?id=DOUE-L-2026-81147
- European Commission. Code of practice on transparency of AI-generated content, published on 10 June 2026 and considered an appropriate voluntary instrument by the Commission and the European AI Board on 8 and 9 July 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- European Commission. Guidelines on the transparency obligations in Article 50 (final version). https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
- Official EU icons for labelling AI-generated content, with rules on placement, accessibility and free-use licensing. https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content
- Draft Organic Law on the responsible use and governance of artificial intelligence. Official Gazette of the Spanish Parliament, Congress, Series A, no. 97-1, 12 June 2026. Under consideration: it appoints AESIA as the central authority and sets out the sanctions regime. https://www.congreso.es/public_oficiales/L15/CONG/BOCG/A/BOCG-15-A-97-1.PDF
- Law 10/2025 of 26 December, regulating customer-service services. Official State Gazette no. 312 of 27 December 2025. In force since 28 December 2025, with a twelve-month adaptation period. https://www.boe.es/buscar/act.php?id=BOE-A-2025-26698