AI changes images – but does it need to be labeled?

Jennifer Schülzky
by Jennifer Schülzky · 27.09.2026

Two laws – two different questions

Whether an image has been manipulated with artificial intelligence is not, at first, a data protection issue.

The GDPR deals with this,

  • whether personal data is processed,
  • whether there is a legal basis for this
  • and what rights the affected individuals have.

The AI Act, by contrast, pursues a different goal.

This is about creating transparency in the use of artificial intelligence. Under certain conditions, viewers should be able to recognize when content has been generated or significantly modified using an AI system.

Therefore, it is not enough to only look at the GDPR or the AI Act.

When does the transparency obligation under Art. 50 AI Act apply?

Article 50 of the AI Act provides for transparency obligations for certain AI-generated or substantially AI-manipulated image, audio, or video content. This is intended to allow viewers to recognize when artificial intelligence has generated content or modified it in a manner that is likely to convey the impression of genuine or unaltered content. At the same time, it is intended to prevent manipulated content from being inadvertently perceived as authentic.

However, it is important to note that not every process involving AI automatically triggers a labeling requirement. In particular, the nature and scope of the change as well as the specific purpose of use are decisive factors.

What exactly is a significant change?

It is here that most misunderstandings are currently arising.

Not every image manipulation is automatically an AI manipulation within the meaning of the AI Act.

Typical examples that occur regularly None significant changes that may occur include:

  • Adjust brightness,
  • Change the contrasts,
  • Optimizing colors,
  • Remove image noise,
  • minor retouching
  • or cropping a picture.

It is different, for example, when

  • People removed or added,
  • Faces exchanged,
  • Background completely replaced,
  • Items inserted
  • or realistic image content is recreated.

In this case, the use of artificial intelligence is not the sole determining factor. Rather, it depends on whether the content of the statement or the perception of the photo is significantly altered as a result of the processing.

In such cases, it must be examined whether the impression of an unaltered photo is created and therefore the transparency requirement under Art. 50 AI Act must be examined.

Our practical example from the previous post

An employee revokes their consent to publish a group photo. The company decides not to completely delete the image but to remove the person from the photo using an AI image editor.

From the perspective of the GDPR, it is first necessary to determine whether the person concerned is still identifiable in the processed record. If this is no longer the case, the original personal processing can be terminated.

However, this does not necessarily conclude the data protection review. Moreover, a second question arises: Does the AI processing lead to a transparency obligation under Article 50 of the AI Act?

For example, if only one employee is removed from a group photo and no misleading or deceptive impression is created as a result, transparent labeling will not usually be necessary.

The removal of a single person does not automatically result in a significant change in the meaning of a picture. Otherwise, this may appear when the editing alters the image in a substantive way or conveys a different overall impression. This could be the case, for example, when people are added or replaced, entire scenes are altered, or completely new image content is created. In these cases, it should be carefully examined whether the transparency requirement under Art. 50 AI Act applies.

The two tests should therefore always be carried out separately: the GDPR answers the question of whether personal data is processed; the AI Act answers the question of whether the use of artificial intelligence must be made transparent to third parties.

When must it be marked?

Companies should, in particular, consider,

  • whether AI was used for image processing,
  • whether the recording was merely technically optimized or substantially changed in content,
  • whether this can create the impression of a real or unchanged photograph for viewers,
  • and whether a transparency obligation under Art. 50 AI Act can be derived from this.

As a general rule, the stronger the AI’s ability to alter the content of an image and the more realistic the result appears, the more likely it is to be examined whether there is a transparency obligation under Art. 50 of the AI Act. Pure technical optimizations such as brightness or color corrections will often be evaluated differently than the removal or replacement of people or the creation of entirely new image content.

GDPR and AI Act Compared

Does an AI-generated image need to be labeled?

Note: This infographic was created with the support of artificial intelligence and subsequently reviewed and revised by our data protection and AI experts.

The graphic is intended as a first guide and does not replace a legal assessment of each individual case. Especially when it comes to marketing campaigns or publicity-oriented publications, a careful evaluation of the specific image manipulation is recommended.

What companies should now consider

From our consulting practice, it is particularly advisable to,

  • Data protection and the AI Act should be evaluated separately,
  • documenting the use of AI for image processing,
  • to check whether individuals are still identifiable after processing,
  • To raise awareness among marketing and HR departments regarding the new transparency requirements,
  • introduce binding internal processes for the release of AI-processed images,
  • and define responsibilities for the labeling of artificially modified content.

Since AI image processing functions are now integrated into many standard programs, appropriate changes are often made without sufficiently considering the legal implications.

Conclusion

The integration of AI image processing into common software facilitates numerous workflows for companies. At the same time, it creates new data protection and regulatory issues that are often underestimated.

In short: The GDPR answers the question of whether personal data may be processed. The AI Act answers the question of whether the use of artificial intelligence against third parties must be made transparent.

Our experience shows that these two examinations are often mixed together. Those who cleanly separate the two regulatory areas from each other and incorporate the relevant requirements early on into existing processes create more legal certainty and reduce the risk of later adjustments.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

Do AI-edited images always need to be labeled?


What is the difference between the GDPR and the AI Act regarding AI-processed images?


Which image modifications are not considered to be a significant change on a regular basis?

When can AI image processing be essential?


Does a group photo have to be labeled if a person was removed using AI?


What should companies take into account organizationally when using AI image processing?