Updated on 19 July 2026

AI Labeling Penalties 2026: Fines, Cease-and-Desist Letters, and Liability

Last updated: July 21, 2026. If you publish AI generated images, videos, or texts without a disclosure, you rightly ask yourself what AI labeling penalty you actually risk, and from when. The short answer: from August 2, 2026 the transparency obligations of Article 50 of the AI Act apply. Violations can be sanctioned with fines of up to 15 million euros or 3 percent of worldwide annual turnover. On top of that comes a lever that in practice often moves faster: the cease-and-desist letter under competition law, for example for unlabeled AI product photos in a shop.

This article puts the three real risks, the regulatory fine, the cease-and-desist letter under German competition law (UWG), and reputational damage, into proper context, explains who is liable (keyword: deployer), shows you the concrete attack surfaces using real world scenarios, and gives you a step by step way to protect yourself, including how to keep proof. No scaremongering, just verified figures.

Key takeaways

  • From when? The labeling obligations under Art. 50 of the EU AI Act apply from August 2, 2026, not August 8, a common mix up of the numbers.
  • How much? The fine range for violations is up to 15 million euros or 3 percent of worldwide annual turnover, whichever amount is higher.
  • 35 million / 7 percent? For labeling this is wrong. That higher range only applies to prohibited AI practices, not to Art. 50.
  • Who is liable? D2C brands, retailers, marketing teams, and agencies are almost always deployers (Art. 50(4)) and carry the visible labeling obligation themselves.
  • Fastest risk: not the fine, but the cease-and-desist letter from a competitor or a qualified association, it can arrive within days.
  • How to protect yourself: label visibly, mark machine readably, and document proof (timestamp plus SHA-256 checksum).
  • Omnibus delay: for now only postpones the machine readable marking for legacy systems to December 2, 2026, not the visible deployer labeling.

Table of contents

  1. The three levels of risk at a glance
  2. The fine: up to 15 million euros, and the 35 million myth
  3. The cease-and-desist letter: the fast, underestimated risk
  4. Reputational risk and platform sanctions
  5. Who is liable? Usually you, as the deployer
  6. Three real world scenarios and their risk
  7. Protecting yourself in 5 steps, including proof
  8. Labeling AI images: a tool instead of manual work
  9. Frequently asked questions (FAQ)

AI labeling penalty: the three levels of risk from missing labeling

Missing labeling is not just an abstract regulatory risk. In practice, three levels operate in parallel, with very different speed and likelihood:

Risk Who enforces it Order of magnitude Speed
Regulatory fine (Art. 50 AI Act) responsible supervisory authorities up to 15 million euros or 3 percent of worldwide annual turnover rather slow (procedure)
Cease-and-desist letter under competition law (UWG context) competitors, qualified associations legal costs, injunction, possibly a contractual penalty fast (days to weeks)
Reputational damage customers, the public, platforms loss of trust, lost reach and revenue immediate (viral)

The deadline for all three is August 2, 2026, not August 8, a common error with no legal basis. You can read details on the dates and the preliminary Omnibus delay in our article on EU AI Act deadlines and fines. How the labeling obligation is structured overall is explained in the overview article on the AI labeling obligation under the EU AI Act.

The fine: up to 15 million euros, and why "35 million" is a myth

For violations of the transparency and labeling obligations under Article 50 of the AI Act, the fine range provides for up to 15 million euros or 3 percent of worldwide annual turnover, whichever amount is higher. That is the verified figure, and the number you should remember.

The figure 35 million euros, or 7 percent, keeps circulating. For AI labeling this is simply wrong. That higher range applies to the most severe violations of the AI Act, for example expressly prohibited AI practices, not to the transparency obligations under Art. 50. Anyone advertising the "AI labeling penalty" as 35 million is spreading a factual error. The real range is serious enough and does not need to be dramatized.

Important context: a fine at the maximum amount will not hit a small D2C shop over a single unlabeled product image. Supervisory authorities assess sanctions based on severity, duration, and intent, a one time oversight is weighed differently than systematic concealment. At the time of writing, the details on which authority is responsible and on the national implementation in Germany were not yet fully settled in every respect, but the substantive obligation itself still applies from August 2, 2026.

Even so, once the obligation applies, missing labeling is a legal violation, and that opens the door to the second, considerably faster acting level.

The cease-and-desist letter: the underestimated, fast risk

While a regulatory procedure takes time, a cease-and-desist letter under competition law can land on your desk within days. Missing or misleading labeling of AI generated content, especially in advertising and e-commerce, can generally be challenged as unfair conduct within the meaning of the German Act Against Unfair Competition (UWG), for example by competitors or qualified associations. The practical appeal of this lever for the sender: it does not depend on a slow authority.

The typical point of attack: unlabeled AI product photos. If an AI generated or AI edited product image creates an impression that diverges from reality (material, color, size, use case), that quickly moves close to a misleading business practice. A cease-and-desist letter then typically aims at three things:

  1. An injunction, you are asked not to repeat the challenged depiction and to sign a cease-and-desist declaration with a contractual penalty attached.
  2. Reimbursement of the legal costs, the other side's attorney fees.
  3. A contractual penalty, if you violate the matter again after signing the declaration.

Whether a broad wave of cease-and-desist letters actually materializes remains to be seen. Still, you should factor in the risk of an individual cease-and-desist letter from a competitor, especially in competitive niches where rivals watch closely. Product images on marketplaces are particularly exposed, you can read what matters there under labeling AI product images on Amazon and eBay and in the guide AI labeling in e-commerce and marketing. (This is a general risk assessment, not legal advice, see the note at the end.)

Reputational risk: the damage no fine notice can capture

The third level appears in no statute, but for many brands it weighs heaviest. If it becomes known that a company is concealing AI content, for example retouched "customer photos" or synthetic testimonials, the loss of trust follows immediately. Screenshots spread faster than any correction, and unlike a fine, the damage cannot be quantified or undone.

There is a fourth, often overlooked consequence: platform sanctions. Meta, Instagram, TikTok, Amazon, and eBay are expanding their own labeling and enforcement rules. Violations of their requirements can lead to reduced reach, ad rejections, or listing suspensions, independent of the law. This level hits your revenue immediately and directly, before the law even has to be invoked. We cover how to label AI advertising in a platform compliant way separately in the article on AI advertising on Meta and Instagram. A particularly sensitive special case is realistic depictions of people and scenes, covered in the article on deepfake labeling.

Who is liable? Usually you, as the deployer

The decisive question is: who bears responsibility? The AI Act distinguishes two roles with different obligations:

  • Provider, Art. 50(2): whoever develops or places an AI system on the market must mark synthetic image, audio, video, and text outputs in a machine readable way (for example via IPTC/XMP metadata, C2PA/Content Credentials, or watermarks). The standard: "effective, interoperable, robust, and reliable as far as technically feasible."
  • Deployer, Art. 50(4): whoever uses and publishes AI content must visibly disclose deepfakes and label AI generated text on matters of public interest. A lighter, proportionate standard applies to art, satire, and fictional formats.

For the typical audience here, D2C brands, e-commerce retailers, marketing teams, and agencies, this is almost always true: you are the deployer. You did not generate the model, but you publish the content, and so you carry the visible labeling obligation under paragraph 4. Relying on "the tool should have marked it" does not relieve you of your role as deployer. We explain in detail who carries which obligation under provider and deployer obligations, and the technical marking methods in detail under C2PA, IPTC, and watermarks.

Role Legal basis Obligation Applies to you if...
Provider Art. 50(2) mark in a machine readable way you offer or place an AI system on the market yourself
Deployer Art. 50(4) disclose visibly (deepfakes, certain texts) you use third party AI tools and publish content

Three real world scenarios and their actual risk

Abstract numbers help little, what matters is how the risk actually plays out. Three typical cases from everyday D2C and e-commerce work:

Scenario 1, an AI product photo in a shop, unaltered product. You have a real product cut out against an AI generated background. The product itself is authentic. Here the risk of misleading customers is low but not zero: if the scene looks like a real use case, a visible notice is advisable. Cease-and-desist risk: low to medium.

Scenario 2, a fully AI generated "lifestyle" image with a fictional user. A synthetic "customer" uses your product in an invented setting. This is the classic point of attack: without labeling, it comes close to a misleading business practice. Cease-and-desist risk: medium to high. Visible labeling is strongly recommended.

Scenario 3, a synthetic testimonial or an AI voice. A "review" comes entirely from a generator. This additionally touches on the reputational risk in its full severity and can qualify as a deepfake under paragraph 4. Risk across all three levels: high. Not advisable without clear disclosure.

The rule of thumb: the more a piece of content pretends to depict a real state of affairs, the higher the combined risk, and the clearer the labeling must be.

Protecting yourself in 5 steps, and how you keep proof

The good news: the effort is manageable once you know what to do. Protecting yourself means five concrete steps:

  1. Review your inventory. Record which assets are AI generated or AI edited, product images, ad creatives, video content, AI texts. Without an inventory there is no solid compliance.
  2. Label visibly (deployer obligation, paragraph 4). Add a clear notice such as "AI generated" or "created with AI" directly on the content itself. A blanket sentence in the imprint or footer is unlikely to be enough, since the labeling must be immediately recognizable to the user. The Commission's official, optional EU icons (variants "fully AI generated" and "partially AI modified," each as SVG and PNG) provide a consistent, recognizable symbol for this. More on that under EU icons for AI content.
  3. Mark in a machine readable way (if you also hold a provider role). Write IPTC/XMP metadata into the file, optionally C2PA and an invisible watermark. This survives downloads and redistribution and can be read on the platform side.
  4. Document proof. This is the point many overlook, and the one that decides matters in a real dispute. If you can prove when which file was labeled how in the event of a cease-and-desist letter or a regulatory inquiry, you are at an advantage. A labeling register with a timestamp and a checksum (SHA-256) turns a mere claim into solid proof.
  5. Anchor it as a process. Make labeling a fixed step in your content and approval workflow, not a manual afterthought. That way no gaps arise with new assets.

You can find format specific details in the guides on labeling AI images, labeling AI videos, and labeling AI texts from ChatGPT. A complete step by step overview is offered by the AI labeling checklist, and you can look up terms in the glossary of AI labeling.

Labeling AI images: a tool instead of manual work

A visible label, machine readable metadata, and airtight proof, generating all of that manually and correctly is tedious and error prone. That is exactly what our free AI labeling tool is for:

  • Drag and drop EU icons onto images and videos, the visible label in seconds.
  • Write machine readable marking at the same time: IPTC/XMP metadata, optionally C2PA/Content Credentials plus an invisible watermark.
  • "Check file", read out and verify labeling that is already present.
  • A labeling register as proof: SHA-256 checksum, timestamp, CSV export, your documentation for a real dispute.
  • Batch processing (up to 50 files as a ZIP) and a REST API for shop and workflow integration.

This covers both levels, the visible label and the machine readable marking, in a single step, and keeps your proof documented. Whether it is product images in a shop, creative assets for Meta ads, or marketplace listings on Amazon and eBay, labeling is done before a cease-and-desist letter can even arise. Get started for free now at ki-kennzeichnen.de.

Frequently asked questions (FAQ)

How high is the penalty if I do not label AI content? For violations of the transparency obligations under Art. 50 of the EU AI Act, fines of up to 15 million euros or 3 percent of worldwide annual turnover are possible, whichever amount is higher. The amount in an individual case depends on severity, duration, and intent.

Is the "35 million euro penalty" for missing labeling true? No. For the labeling obligation under Art. 50, the verified range is up to 15 million euros, or 3 percent. The circulating figure of 35 million (or 7 percent) applies to the most severe violations of the AI Act, for example prohibited practices, not to the transparency obligations.

From when does the AI labeling penalty apply? The obligations under Art. 50 apply from August 2, 2026, not August 8. A preliminary Omnibus delay to December 2, 2026 only affects the machine readable marking for legacy systems placed on the market before August 2, 2026, not the visible deployer labeling.

Can I be sent a cease-and-desist letter for unlabeled AI product photos? In principle, yes. Missing or misleading labeling of AI generated content can become relevant under competition law (UWG context) in e-commerce and can lead to a cease-and-desist letter from competitors or qualified associations. This is a general risk assessment, not a substitute for legal advice.

Who is liable, the AI provider or me? Both, but for different obligations. The provider must mark in a machine readable way (paragraph 2), the operator/deployer must label visibly (paragraph 4). As a D2C brand, retailer, or marketing team, you are usually the deployer and carry the visible labeling obligation yourself.

Do I have to label every AI edited photo? What matters is whether the content deceptively recreates a real state of affairs. Purely minor, clearly insignificant edits are assessed differently than fully synthetic or substantially altered depictions. For deepfakes and misleading product depictions, visible labeling is the safe path, art and satire are held to a lighter standard.

Is a notice in the imprint or footer enough? Likely not. Labeling should happen on the content itself so that it is immediately recognizable to users. A central, collective notice generally does not satisfy the recognizability requirement.

Do I have to use the official EU icons? No. The icons provided by the EU Commission are optional. They do offer a consistent, recognizable symbol and make clear, immediate labeling easier, a clear text notice of your own is equally permitted.

How do I prove that I labeled on time? Through a labeling register with a timestamp and an SHA-256 checksum per file. The AI labeling tool creates this proof automatically and exports it as CSV.

What does the Digital Omnibus change about my obligation? Under the preliminary status (May 2026), the Omnibus only postpones the machine readable marking (paragraph 2) for legacy systems to December 2, 2026. The core deadline of August 2, 2026 and the visible deployer labeling (paragraph 4) remain unaffected. The delay is preliminary and may change.

Sources


This article reflects the status as of July 21, 2026, and does not constitute legal advice. The Omnibus delay is preliminary and may change. Please consult legal counsel for your specific situation.

Read more