Updated: September 3, 2026 · Docs · Law · Clothoff AI Editorial Team

What is the EU AI Act?

Europe’s risk-based AI law and the Article 50 duty to mark synthetic images, audio, video and text — dates, fines, and what it means for US tools reviewed here.

General information about EU and US law for readers of tool reviews, not legal advice. Questions: editorial@clothoff.ai.

The EU AI Act is Regulation (EU) 2024/1689, the European Union’s risk-based law for artificial intelligence, in force since August 1, 2024 and generally applicable from August 2, 2026. Its Article 50 requires providers of generative AI to mark synthetic images, audio, video and text in a machine-readable way and requires deployers to disclose deepfakes.

Key provisions at a glance

Checked against the linked sources on September 3, 2026; no editor scores here (how we rate).

LawEffective dateWhat it coversPenaltySource
Art. 5 — prohibited practicesFeb 2, 2025Banned uses: manipulation, social scoring, some biometricsUp to €35 million or 7% of turnoverEUR-Lex
Chapter V — general-purpose AIAug 2, 2025Documentation and copyright duties for GPAI providersUp to €15 million or 3%Commission
Art. 50(2) — machine-readable markingAug 2, 2026; grace until December 2026 for systems already on the marketProviders mark synthetic output as AI-generatedUp to €15 million or 3%Commission
Art. 50(4) — deepfake disclosureAug 2, 2026Deployers disclose that image, audio or video is a deepfakeUp to €15 million or 3%EUR-Lex
AI Omnibus — new prohibitionDecember 2026Bans systems generating non-consensual intimate content or CSAMProhibited-practice tier (Art. 5)Commission

How is the AI Act structured?

The regulation sorts AI systems into four tiers: unacceptable risk (banned), high risk (conformity assessment), transparency risk, and minimal risk with no new duties. Image and video generators are not high-risk by default; they sit in the transparency tier, which is why Article 50 is the provision that matters for the tools reviewed on this site.

The timeline is staggered: prohibitions since February 2, 2025, general-purpose AI duties since August 2, 2025, most other rules since August 2, 2026. The AI Omnibus, in force since July 27, 2026, moved high-risk deadlines to December 2, 2027 and August 2, 2028 but left the Article 50 dates in place.

What does Article 50 require for synthetic images?

Article 50(2) obliges providers to mark outputs “in a machine-readable format and detectable as artificially generated or manipulated.” Article 50(4) obliges deployers to disclose a deepfake — content that resembles existing persons and would falsely appear authentic, per Article 3(60). For evidently artistic or satirical work the disclosure may be limited.

The Commission published a Code of Practice on Transparency of AI-generated Content in June 2026 and offers three optional icons. Deepfakes made before August 2, 2026 need no retroactive label. Marking in practice relies on C2PA credentials or invisible watermarks such as SynthID.

Does the AI Act apply to US-based undress apps?

Yes, when the system is placed on the EU market or its output is used in the Union — the same reach the GDPR uses. A US operator that ignores the marking duty faces fines of up to €15 million or 3% of worldwide turnover.

The AI Omnibus went further: from December 2026 it prohibits AI systems that generate non-consensual sexually explicit or intimate content — the Commission’s own example is “nudification” apps. A label never legalizes an image: it remains NCII and, in the United States, a federal offense under the TAKE IT DOWN Act.

Why does this matter for a US review site?

Clothoff AI generates and stores no images, so it is not a provider under Article 50. Sample previews in reviews come from third-party tools and carry a visible Art. 50 label plus a caption stating that no real person is depicted, as set out in the AI content policy. Each review records whether a tool marks its output with metadata or a watermark. This page is general information, not legal advice.

Questions about EU AI Act

Frequently asked questions

Does the EU AI Act ban undress apps?

From December 2026, yes for one category: the AI Omnibus added a prohibition on systems that generate non-consensual sexually explicit or intimate content. Ordinary image generators stay in the transparency tier and must mark output under Article 50(2). Unlawful uses such as NCII were already covered by criminal law.

When did labeling of AI-generated content become mandatory?

The Article 50 transparency rules apply from August 2, 2026. Generative systems placed on the market before that date have a grace period for the machine-readable marking duty until December 2026. Deepfakes created before August 2, 2026 need no retroactive label, although the Commission encourages one.

Does the act apply to a company with no office in Europe?

Yes. Regulation (EU) 2024/1689 covers any provider placing an AI system on the EU market and any deployer whose output is used in the Union, regardless of where the company is established. The test is where the user is and where the effect occurs, mirroring the GDPR approach.

How is an image marked as synthetic in practice?

Two complementary techniques dominate: signed provenance metadata such as C2PA content credentials embedded in the file, and invisible watermarks written into the pixels. Article 50(2) requires the mark to be machine-readable; Article 50(4) adds a visible disclosure to the viewer whenever the content is a deepfake.

What are the fines for breaking Article 50?

Article 99(4) sets the ceiling at €15 million or 3% of total worldwide annual turnover, whichever is higher. Prohibited practices under Article 5 carry up to €35 million or 7%. EU institutions face fines of up to €750,000, and small companies receive proportionate amounts under the same article.

Does an AI label make a non-consensual image legal?

No. Article 50 is a transparency rule; it adds an obligation and removes none. A synthetic intimate image of a real person without consent remains NCII in the EU and is a federal crime in the United States under the TAKE IT DOWN Act, which also gives victims a 48-hour removal route.