A client brought me a question recently that sounds trivial until you actually try to answer it. The company wanted an AI-generated dandelion as its key visual, a specific look that doesn't exist as a real photograph. It reads as photorealistic. No deepfake in the colloquial sense, no person, no place, no event. Still: does this need a label?

Short answer, no. The more useful answer is why, because that's what tells you where the line actually sits for the next image you're less sure about.

Two obligations, two different addressees

The EU AI Act's Article 50 splits into two obligations that get conflated constantly, and the mix-up is where most of the confusion in this space comes from.

Article 50(2) requires providers of generative AI systems (Midjourney, DALL-E, Adobe Firefly, and similar tools) to mark their outputs in a machine-readable format. This is where standards like C2PA operate: signed metadata embedded in the file, invisible to the viewer, no visual badge. That obligation sits with the tool vendor, not with the business using the tool.

Article 50(4) requires deployers, meaning businesses publishing AI content, to visibly label deepfakes and AI-generated text on matters of public interest. This is the obligation that actually touches most company websites, and it's the one behind the dandelion question.

Why the dandelion gets a pass

The legal definition of a deepfake in Article 3(60) requires that the content resembles real people, places, objects, institutions, or events, and would falsely appear authentic. The key word isn't whether the category exists in reality. Dandelions obviously exist. What matters is whether the image claims to depict one specific, identifiable instance that can be found in the world. Type versus token, to borrow a term from philosophy of language.

A dandelion as a species is real. But the image doesn't claim to show a particular dandelion that stands or stood somewhere specific. Nobody looks at it and wonders which dandelion, exactly. Without that individual reference, there's no false claim about authenticity for the rule to catch.

Compare that to an AI image claiming to show the Brandenburg Gate, or a synthetic video showing a recognizable person in a scene that never happened. There, a concrete reference object exists, and the image makes a claim about it that could be false.

Where it actually gets hard

The German law firm Härting Rechtsanwälte laid out exactly where this clean distinction breaks down, in their overview of the AI Act's transparency obligations. They flag photorealistic but entirely fictional depictions of people as unresolved, things like realistic AI models used in online shops or virtual influencers with no real-world counterpart.

The reason faces are the sticking point and dandelions aren't comes down to perception, not law. A brain reads faces as identity, not category. A photorealistic but fictional face still registers as a specific individual, even though that individual doesn't exist anywhere. That's precisely the kind of deception Article 50(4) is built to prevent, and it simply doesn't arise with a flower.

For a standard stock-photo scenario, three people laughing in an office, used purely as a placeholder with no location or identity claims in the surrounding text, the case against a labeling requirement is fairly strong, mostly because the context doesn't suggest authenticity either. That said, this isn't settled with certainty. The European Commission's final guidelines on Article 50 are still pending as of this writing.

A four-step test

Based on the cases decided or discussed so far, a four-step test can sort most images a business might publish.

Flowchart for assessing the labeling requirement under Article 50 of the EU AI Act: four questions moving from AI generation through individual reference and realism to context, ending in a labeling-required or no-labeling-required outcome

The four questions, in order:

1. Was the content AI-generated or substantially altered? Simple retouching falls under the assistive-function exemption and stops here.
2. Does the image claim to show one specific, identifiable thing, rather than a category? No individual claim, no further analysis needed, same as the dandelion.
3. Does it look realistic enough to pass as authentic? Content that's clearly artistic or marked as fictional falls under the weaker exemption described in the draft guidelines.
4. Does the surrounding context imply a real, documented situation? A clearly generic stock image is a different thing from one captioned "our team" or "real customers."

Only when all four questions land on yes does a labeling obligation under Article 50(4) currently apply.

Running in parallel to this, independent of the image test, is the obligation to label AI-generated text on matters of public interest, unless a human holds editorial responsibility for the publication.

What this means in practice

If you're using a generic, stylized visual as a key image, the way our client did, you don't need to worry about a visible label right now. If you're working with AI-generated people meant to pass as real employees, customers, or testimonials, you're in the exact gray zone that isn't fully resolved yet, and that's a risk worth taking on deliberately rather than by accident.

Regardless of the legal requirement, one free step is worth doing anyway: don't strip C2PA metadata a tool adds on export. It doesn't satisfy any obligation on your end as a deployer, but it costs nothing and adds a layer of transparency that tends to help trust rather than hurt it.

We're working on a short interactive tool that applies the test above directly to a specific image. We'll link it here once it's live.

Source: Härting Rechtsanwälte, Transparency obligations under the AI Act