BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/AI Generated Models in Your Product Photos
IndustrySeptember 14, 2026
Read · 5 min
ai generated models · product photography

AI Generated Models in Your Product Photos

An invented face can still count as a deepfake, and a generated customer cannot endorse anything. The permissions and labels a shop needs before the shoot.

Key takeaways
  • A wholly invented person in your product photos can still fall inside the EU definition of a deepfake, because the test asks whether the subject could plausibly exist, not whether they do.
  • Running a shop for a living makes you a deployer under the AI Act. The personal use exemption covers someone posting for fun, not someone earning from it regularly.
  • A deployer's label has to be visible to a person without special tools. Relying on the invisible marking your image generator embedded does not discharge the duty.
  • California has made certain digital replica clauses unenforceable since 1 January 2025 when the contract lacks a reasonably specific description of the intended uses.
  • An endorsement from someone who does not exist is deceptive on its face, which puts a generated smiling customer in a different category from a generated background.
  • The practical work is one page: what the image shows, what permission covers it, what label it carries, and where the original files live.

A product shoot costs a day, a photographer, a studio and a model. An image generator costs a few cents and answers immediately. For a small brand with forty items to photograph, the arithmetic is not close, which is why synthetic people are appearing in independent shops rather than only in the big campaigns that got written about.

The legal questions arrived at the same time and they are not the ones most people expect. Copyright in the generated image turns out to be the least of it. What matters is whose face it resembles, whether the viewer can tell it is generated, and whether the image is doing the job of a testimonial.

Does an invented person count as a deepfake?

Possibly, and the reasoning is worth following because it surprises people. The Commission's FAQ on the Article 50 transparency obligations sets out the definition from Article 3(60) and lists three cumulative criteria that content must meet to be a deepfake.

The first is resemblance, meaning a high level of similarity between the content and the subject it simulates. The second is described as existing, and this is the clause that catches synthetic models: the simulated person, object, place or event needs to resemble someone or something that exists, can plausibly exist, or could have plausibly existed in reality. The third is that the content would falsely appear to a viewer to be authentic.

A photorealistic invented woman wearing your jacket satisfies the first criterion against the general category of human beings, plainly satisfies the second because such a person could exist, and satisfies the third if nothing on the page says otherwise. The intuition that you are safe because you invented the face does not survive contact with the wording.

Breakdown diagram of the three cumulative criteria that make image content a deepfake under the AI Act, covering resemblance, plausible existence and false appearance of authenticity
All three have to hold. The middle one is where synthetic models stop being obviously outside the definition.

Are you a deployer if you run the shop alone?

Yes, and the FAQ is direct about where the line sits. Deployers are persons or bodies using an AI system under their authority, excluding use for personal, non professional activities. Generating images in your own capacity and posting them for fun is a personal activity outside the Act's scope.

The moment the activity produces an economic benefit on a regular basis, or forms part of a business, trade, occupational or freelance activity, the same natural person becomes a deployer. A sole trader photographing stock for a shop is squarely in that description. There is no small business carve out here, only a hobby carve out, and selling is not a hobby.

What a deployer owes is a clear label on deepfake content. The detail that trips people up is the form it must take. The FAQ states the disclosure has to be clear and distinguishable, understandable and perceivable by a person through visible or audible labels, without needing any specific technical tools or dedicated actions. It then says plainly that deployers cannot simply rely on the machine readable marking embedded by the provider under Article 50(2) to discharge their own obligation.

Which means the invisible provenance data your generator writes into the file is not the label. It is useful, it is evidence, and it is worth keeping, as we discussed in what a content credential actually proves about an image. It is not a substitute for a line a customer can read.

Which situations need which permission?

Four cases come up constantly and they have genuinely different answers. Treating them as one question is how shops end up with either useless paperwork or none.

What you madeWhose permissionVisible labelThe real risk
Invented person wearing your productNobody's, if the face resembles no specific individualLikely yes in the EUUnlabelled content that reads as a real photo
A real model's likeness reused by a generatorThe model's, in writing, with uses listedLikely yesA replica clause that turns out to be unenforceable
AI edit of a genuine photo of your productNone beyond the original shootDepends how material the edit isMisrepresenting the product itself
Generated customer giving a testimonialCannot be cured by permissionA label does not fix itAn endorsement by a person who does not exist

The last row is the one to read twice, because it is the only case where no amount of disclosure makes the thing acceptable.

Can a generated person endorse your product?

No, and this is older law than anything about AI. The FTC's endorsement guides guidance for businesses addresses the underlying principle in its discussion of purchased social proof: approval from non existent people, or from people with no experience of the product, is clearly deceptive, and both the buyer and the seller of it can face enforcement.

The medium does not change the analysis. A five star quote beside a generated face is a claim that a customer had an experience. Nobody had that experience. That it was produced by a model rather than bought from a click farm is irrelevant to the person reading it, which is the only perspective that matters in deception law.

The boundary is about what the image asserts. A synthetic person modelling a coat asserts that the coat looks like this on a body of roughly that shape. A synthetic person saying the coat kept them warm in Helsinki asserts an experience. The first is styling. The second is a testimonial and it is off limits.

Card listing three steps to complete before a synthetic photo shoot, listing the intended uses, deciding the visible label, and keeping the original source files

What does a model release need to say now?

If you are working with a real person whose likeness might later be used to generate images, the contract has to be more specific than it used to be, and one jurisdiction has made that concrete.

California's AB 2602 added Section 927 to the Labor Code, approved by the Governor on 17 September 2024. Its bill text makes a provision in a personal or professional services agreement unenforceable, as it relates to a new performance fixed on or after 1 January 2025 by a digital replica, when three conditions all hold.

The provision has to allow creation and use of a digital replica of the individual's voice or likeness in place of work they would otherwise have performed in person. It has to lack a reasonably specific description of the intended uses of that replica. And the individual has to have been unrepresented, meaning neither by legal counsel who negotiated the licensing terms with the commercial terms stated clearly in a signed writing, nor by a union whose collective agreement expressly addresses digital replica use.

Read as an instruction rather than as law, it says something simple. If you want to generate images from a person's likeness, write down what you will generate and where it will appear, in enough detail that the person understood what they agreed to. A release saying all media in perpetuity was always lazy. In this specific context it is now the thing that voids the clause.

Note

The statute's definition of a digital replica includes the case where the individual did perform or appear, but the fundamental character of that performance or appearance has been materially altered. Heavily editing a real shoot with generative tools can land inside the definition even though a genuine session took place.

Does the same duty apply to your written copy?

No, and this is the most useful piece of relief in the whole area, because a lot of shop owners have quietly concluded that every AI drafted product description now needs a disclaimer.

The FAQ describes the text obligation narrowly. Under Article 50(4), deployers must clearly label AI generated or manipulated text that is published with the purpose of informing the public on matters of public interest. A product description for a jacket is not a matter of public interest. Neither is a shipping policy, a newsletter about a sale, or an answer in your help centre.

So the asymmetry is deliberate. Generated images of people carry a visible labelling duty and generated commercial prose generally does not. If you have been holding back on drafting copy with a model because of the AI Act, that particular worry was misplaced, though the ordinary rules against misleading claims apply exactly as they always did. The separate question of marking your own text for other reasons is covered in whether watermarking published text does anything useful.

What should the label actually say?

Short, factual, in the same visual language as the rest of the page. Something on the order of image generated with AI, placed where a person looking at the image would see it, is enough to meet a requirement written around whether a viewer is informed.

Three placement mistakes are worth avoiding. A label in the alt text alone is invisible to a sighted viewer and does not meet a requirement about perceivability. A label in the site footer is not attached to the image and tells a person browsing a product page nothing. A label that only appears after a click is a dedicated action, which is the thing the guidance rules out.

There is one softening worth knowing about. The FAQ notes that some deepfakes form part of evidently artistic, creative, satirical or fictional works, and that for these the obligation narrows to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. A stylised illustration for a campaign has more room than a photorealistic image on a product page. A shop should not lean on this. An image whose whole purpose is to look like a photograph of a real garment on a real person is not an evidently creative work.

When is a real shoot still the better buy?

More often than the price comparison suggests, and for reasons that have nothing to do with law.

Fit is the obvious one. A generated image shows a garment as the model imagines it drapes, which is a guess dressed as a photograph, and returns driven by fit disappointment cost more than the shoot would have. Anything where the customer is buying the way a thing sits on a body deserves a real body.

Texture and scale are the quieter failures. Generators are confident about surfaces and unreliable about how big something is relative to a hand, which is exactly the judgement a buyer makes from a photo. The cases where synthetic imagery genuinely wins are the ones with no such judgement to make: backgrounds, lifestyle context around a product photographed for real, seasonal variations of a scene you already own.

A sensible split for most shops is real photography for the product and generated imagery for everything around it. That keeps the labelling question narrow, keeps the factual claims anchored to something that exists, and still removes most of the cost.

What about photos of your own customers?

Different problem, same discipline. Photographs sent in by buyers are somebody else's likeness, and running them through a generator to clean them up, restyle them or place them on a different body crosses from editing into replication quickly.

Two rules keep this simple. Ask before you publish, in a message that says what you intend to do with the image, including whether it will be altered. And keep the original alongside whatever you published, so that the difference between the two is something you can show rather than describe.

Try on features raise the same question from the other end, because the customer's body becomes an input rather than an output. The practical and legal considerations there are their own subject, covered in what a virtual try on actually does with a customer photo.

Does the platform have its own rules?

Almost always, and they are usually stricter and faster moving than the law. Marketplaces and ad platforms each run their own policies on generated imagery, and enforcement there is immediate: a listing comes down or an advert is rejected without anybody weighing a legal argument. The marketplace layer is where most shops actually get caught, and it is set out in the rules marketplaces apply to AI generated product images.

The important practical difference is that platform rules generally care about whether the image misrepresents the product, while the transparency law cares about whether the viewer knows the image is generated. A picture can satisfy one and fail the other. A photorealistic synthetic model wearing an accurately rendered jacket misrepresents nothing and is still unlabelled generated content.

What to write down before you start

One page, and it does not need a lawyer to draft the first version.

Write down which of the four cases above you are in, because the answer changes everything downstream. Write the intended uses in specific terms, naming the channels rather than saying marketing. Decide the wording of the visible label and where it sits, then use the same wording everywhere so it becomes a recognisable convention on your site rather than an apology. Record where the source files and any releases live, with dates.

Then keep the originals. Every dispute in this area is settled by showing what you started with, and the shops that cannot produce that are the ones who spend money on the argument. A folder with dated files is worth more than any policy document.

Two habits make that folder useful rather than merely large. Name files so the case is legible from the name alone, separating a generated image from an edited photograph, because in six months nobody will remember which was which. And keep the prompt or the settings beside the output. The prompt is the closest thing you have to a record of intent, and intent is what a regulator or a platform reviewer is actually assessing when they ask why an image exists.

If you want a starting structure for the policy itself rather than the paperwork, our own is published at the MaShop AI policy page, and the shape of it transfers even though the details will not.

None of this makes synthetic photography a bad idea. It makes it a production process with a paperwork step, which is exactly what photography with real people has always been. The shops that treat it that way will keep the cost advantage. The ones that treat it as free will discover the price later.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building