When AI copy or AI images in a marketing email need a label under Article 50 of the EU AI Act: the deep fake test, the text exception, dates and fines.

Article 50 of the EU AI Act is the transparency rule for AI-generated content. It requires companies that build generative AI tools to mark output as machine-made, and businesses that use those tools to disclose deep fakes and some AI-written text. It has applied since August 2, 2026.
For email, the short version: an AI-drafted promotional email needs no label. A photorealistic AI image of a person, place or product that subscribers could take for real probably does.
This is a practitioner's reading of the regulation and the Commission's guidance, not legal advice. If your emails sit close to a line drawn here, ask counsel.
Three of its seven paragraphs matter for email (official text on EUR-Lex). Paragraph 2 binds tool makers:
"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."
Paragraph 4 binds the businesses using them, first for deep fakes:
"Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated."
Then for text:
"Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."
Paragraph 5 sets timing and form:
"The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements."
In email, first exposure is the email, so a landing page disclosure is too late.
Article 3(60) defines a deep fake as "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful."
Under Article 113 the regulation "shall apply from 2 August 2026", and Article 50 is not among the listed exceptions.
The Digital Omnibus on AI, proposed in November 2025, became Regulation (EU) 2026/1744, published July 24, 2026 and in force three days later. It moved the high-risk rules to December 2027 and August 2028. For Article 50 it added one transitional rule, Article 111(4):
"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026."
As Morgan Lewis put it in August, "The 2 December transition period does not postpone the deployer duties."
| Date | What happened or applies | Who it binds |
|---|---|---|
| June 10, 2026 | Final Code of Practice on marking and labelling published | Voluntary signatories |
| July 8-9, 2026 | Commission and AI Board assess the Code as adequate | Voluntary signatories |
| July 20, 2026 | Commission adopts final Article 50 guidelines | Non-binding guidance |
| August 2, 2026 | Article 50 applies, including deep fake and text disclosure | Providers and deployers |
| December 2, 2026 | Marking deadline for generative systems on the market before August 2, 2026 | Providers only |
A provider develops an AI system, or has one developed, and markets it "under its own name or trademark". A deployer is anyone "using an AI system under its authority" outside personal use. Make emails with an AI platform, image generator or chatbot and you are the deployer.
The Commission's guidelines settle three common questions:
Being outside the EU does not help if you foresee use in the Union, for example "by directing or authorising distribution within the Union". On our reading, mailing EU subscribers is exactly that. Metadata does not help either. Deployers "cannot rely on the machine-readable marking embedded in the content by the provider", because readers cannot see it.
The guidelines split the text rule into three tests, and all must hold.
Published. The text reaches "an indeterminate, fairly large number of unrelated, potential readers", subscription or not. One-to-one sales emails and internal mail are not. On our reading, a newsletter to a large list plausibly is, and one with a public archive almost certainly is.
To inform the public. Short texts that do not "materially communicate knowledge, opinions or facts" are out.
On matters of public interest. Politics, public health, consumer safety, the environment, and "any economic, financial, political, scientific, or cultural development that may be relevant subject of public debate".
Most marketing email fails the third test. The guidelines put this out of scope: "AI-manipulated text that is part of a company's advertisement or product descriptions (not including any claims related to e.g. health, consumer safety or sustainability)."
So sales, launches, welcome series and cart reminders need no text label. Look harder at:
The bar is real. Review means "the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge", and "fact-checking the accuracy of the content is a minimum requirement". Spell-checks, "the mere existence of an editorial policy", automated review and "cursory editorial approval without substantive engagement" do not qualify.
Order matters: "Any substantive AI intervention occurring after the human review or editorial control process has taken place will therefore cause the exception to become void." Ask the AI to "make the intro punchier" after sign-off and you need a fresh approval.
The identity and contact details of whoever holds editorial responsibility "should be made publicly available on an easily findable location". An "Edited by" footer line does it. The Code of Practice asks signatories to record who holds that responsibility and their review process, not each review.
Images are where most email teams will actually owe a label.
"Existing" includes the plausible. A subject counts if it resembles "someone or something that exists, can plausibly exist or could have plausibly existed in reality". As Bird & Bird notes, "a photorealistic portrait of an invented person remains within the definition". Your AI "happy customer" is not exempt because she never existed.
Context and audience decide "falsely appear authentic". The objective test weighs realism, message, setting and foreseeable audience, so intent is irrelevant. Redistribution beyond that audience does not count, and the guidelines cite "a corporate newsletter" as a limited channel.
| Image in your email | Deep fake? | Basis in the Commission guidelines |
|---|---|---|
| Photorealistic AI person using your product | Likely yes | Realistic AI avatars and personas count as "persons" |
| AI image of a real celebrity or your CEO | Yes | Examples include a celebrity influencer in an ad and a synthetic CEO avatar |
| AI product shot that makes the product look better than it is | Yes | "can affect the audience's perception and mislead as to the actual product appearance" |
| Real product photo on an AI-generated background | Usually no | Not a deep fake "as long as the ad is not likely to mislead" |
| AI colour correction, relighting, background extension, resizing | No | Minor edits for advertising and packaging |
| Obviously fantastical scene (mice arguing about cheese, a sphinx over the Eiffel Tower) | No | Both listed as not deep fakes |
| Flat illustration, icon or abstract gradient | No | Our reading: resembles no real subject |
Don't count on the lighter regime for "evidently artistic, creative, satirical, fictional or analogous" work. Content that is "exclusively informative or commercial" is excluded, and a teleshopping-style video of simulated consumers is listed as not creative. A label also does not make an image lawful. Misleading advertising rules, personality rights and the GDPR still apply.
The Code of Practice on Transparency of AI-generated Content is voluntary, and the Commission notes that adherence "does not constitute conclusive evidence of compliance". It is still the most concrete label guidance around, so follow it either way. For images it asks for:
In email we'd do three things:
alt="AI-generated image: a woman in a rain jacket on a ferry". Screen readers read alt text, not icons.For in-scope AI text nobody reviewed, put a visible statement at the top of the email, not just the footer.
AI agents that converse over email. Article 50(1) makes providers disclose AI interaction, which needs "a bidirectional exchange of information". On our reading a newsletter is not covered, but an AI agent answering replies is, and the guidelines' example is an AI-agent email "that features an AI label at the top".
Fines. Under Article 99(4), breaches of "transparency obligations for providers and deployers pursuant to Article 50" carry fines "of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher". For SMEs and start-ups, whichever is lower. Member States set their own penalties within those caps.

Run each AI-made asset through this before scheduling. Text and images take different paths.
Then make it routine. Tag AI images at creation as generated, AI-edited or untouched, and add a deep fake check to pre-send QA. Name an editor for informational emails who approves last. Ask AI vendors whether their output carries machine-readable marking and whether they rely on the December 2 transition, as Morgan Lewis recommends.
Brew's AI writes copy, designs emails and generates and edits images, so you are the deployer for emails built in it. Three things help.
send_email returns confirmation_required first. Brand API-key connections skip that pause, per the authentication docs. The click counts as human review only if the approver reads and fact-checks the email.image-style.md is the art direction Brew reads before making any image. To avoid labels, add a line to its avoid list such as "no photorealistic people, use illustration or real product photos". email-design.md explains the brand files.Labels and the EU icon are a manual step, and the email audit does not screen for deep fakes, so apply the labelling steps above.
Usually not for the text. Advertising copy and product descriptions sit outside the text rule unless they make health, consumer safety or sustainability claims. AI images that could pass as real photos of people, places or products are deep fakes and need a visible label.
Only one part. Regulation (EU) 2026/1744 gave providers of generative AI systems on the market before August 2, 2026 until December 2, 2026 for machine-readable marking. Deployer duties, including labelling deep fakes and in-scope AI text, have applied since August 2, 2026.
It can be. "Existing" covers subjects that "can plausibly exist or could have plausibly existed", so a photorealistic invented person counts if your audience could take it for a real photo. A clearly stylised or fantastical illustration does not.
A person with relevant knowledge examines the substance, and fact-checking is the minimum. A spell-check or quick approval does not count, and any substantive AI edit after sign-off cancels the exception. A named person or the company must hold editorial responsibility, with easy-to-find contact details.
For other rule changes this year, see the September State of Email. For copy a reviewer can check quickly, see how to write marketing emails.
