Explainer

Is it legal to remove AI metadata from an image?

What the EU AI Act, US copyright law, platform terms and our own rules each say, and why the risk sits in what you publish.

Updated 23 September 2026

None of the rules we could find makes it illegal to delete metadata from a file you own. They regulate other things: what an AI provider must put into its output, what a business must tell people when it publishes a realistic fake, and what you may strip from someone else’s copyrighted work. So whether removing AI metadata is legal mostly turns on what you do with the image next.

This page is a reading of public texts, not legal advice. For a real decision, ask a lawyer where you live.

The EU AI Act puts duties on providers and deployers

Article 50 of the EU AI Act applies from 2 August 2026. For images it does two things. They land on different people.

Paragraph 2 is about providers, the companies whose systems generate images. Their outputs must be “marked in a machine-readable format and detectable as artificially generated or manipulated”, as far as that is technically feasible. Systems that only assist standard editing, or don’t substantially alter the input, are exempt. The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) gives systems already on the market before 2 August 2026 until 2 December 2026 to comply with this marking duty; new ones get no grace period.

Paragraph 4 is about deployers, and this is where a person publishing images comes in. Anyone who uses an AI system to generate or manipulate a deep fake must disclose that it was artificially generated or manipulated, at the latest on first exposure. Two definitions in Article 3 narrow it a lot. A deep fake is AI-generated or manipulated content that resembles existing persons, objects, places, entities or events and “would falsely appear to a person to be authentic or truthful”. A deployer excludes anyone using the system “in the course of a personal non-professional activity”. Evidently artistic, satirical or fictional work only has to disclose in a way that doesn’t spoil the work.

Who Article 50 of the EU AI Act asks to do what for images, as read on artificialintelligenceact.eu, 23 September 2026
WhoDutyFrom
Provider of an image generatorMark outputs in a machine-readable, detectable way (Art. 50(2))2 August 2026; 2 December 2026 for systems already on the market
Professional deployer publishing a deep fakeDisclose that it is AI-generated or manipulated (Art. 50(4))2 August 2026
Someone using an AI tool for personal, non-professional purposesNot a deployer under Art. 3(4), so Art. 50(4) does not reach themNothing under Art. 50(4)

Fines for breaking Article 50 go up to €15 million or, for a company, 3% of worldwide annual turnover if that is higher (Article 99(4)). For small and medium-sized firms the lower of the two figures is the cap (Article 99(6)).

As we read it, Article 50 has no clause addressed to someone who removes a mark; the duty to disclose sits with the deployer whether or not the file still carries one. A business in the EU that strips the credentials from a realistic AI image and publishes it without saying so has a problem, and the problem is the missing disclosure.

Stripping the same file for a personal album gives Article 50 nothing to bite on.

Removal does come up in the Commission’s Code of Practice on Transparency of AI-Generated Content, the voluntary code Article 50(7) asks for, published in final form on 10 June 2026. Under its Measure 1.2, providers that sign it will put “a prohibition of the intentional removal of or tampering with metadata markings by deployers or any other third party” into their terms, with exceptions for legitimate purposes such as security audits and research. So the ban arrives as a contract term from the generator, not as a clause of the Act. Adobe’s terms already read that way, as the Firefly and Photoshop guide quotes.

Two things we don’t know. We haven’t checked which generators have signed the code or changed their terms because of it. And we read Article 50 and the definitions with this question in mind, not the whole Act.

US copyright law: section 1202

The US rule that sounds closest is section 1202 of the Copyright Act, added by the DMCA. It forbids anyone, “without the authority of the copyright owner or the law”, from intentionally removing or altering “copyright management information” while knowing, or for civil claims having reasonable grounds to know, that it will help cause or hide an infringement. Its list of what counts includes the title, the name of the author, the name of the copyright owner, terms of use, and identifying numbers or links to them. It excludes personally identifying information about a user of the work.

On your own photo, you are the copyright owner. The authority is yours. The textbook 1202 case is the other one: taking a photographer’s picture, deleting the byline and copyright notice from its metadata, and republishing it. Whether a C2PA manifest that only says “made with an AI tool”, with no author or owner in it, counts as copyright management information is a question we haven’t seen a court answer.

Platform rules are the ones you will meet first

Meta’s Instagram help page, as we read it on 23 September 2026, requires a label on photorealistic video and realistic audio that was generated or altered, and says it doesn’t require you to label images, while labelling images its systems detect. It warns there may be penalties for not labelling content as required. The guide to the AI info label covers what triggers it on edited real photos. Other platforms have their own terms, which change more often than laws do.

Our rules

Our terms of use say to upload only images you created or are licensed to modify, not to pass off AI-generated content as made by a person where that would mislead someone, and to keep disclosing where the law or a platform asks you to. The acceptable use policy adds that WipeTheAI is not for getting around a law or platform rule requiring AI content to be labelled, naming the EU AI Act’s transparency duties. We can refuse jobs, block access and delete images when those rules are broken. We can’t see what you publish afterwards, which is why the rules are written about publishing.

Sources

  1. EU AI Act, Article 50: transparency obligations
  2. EU AI Act, Article 3: definitions (deployer, deep fake)
  3. EU AI Act, Article 99: penalties
  4. Digital Omnibus on AI, Regulation (EU) 2026/1744 (new Article 111(4))
  5. European Commission: Code of Practice on Transparency of AI-Generated Content (final, 10 June 2026)
  6. 17 U.S. Code § 1202: integrity of copyright management information
  7. Instagram Help Center: label AI content on Instagram
  8. Apple Personal Safety User Guide: manage location metadata in Photos