AI Output Copyright - Generated Content IP Strategy
The marketing team ships an AI-generated hero image for the Q3 campaign. Six months later, a U.S. district court holds in a related matter that purely AI-generated outputs are uncopyrightable. The campaign asset sits in the brand library as a public-domain work, competitors can copy it without consequence. The procurement contract with the generative-image vendor includes an indemnity, but the indemnity is defense-cost only, capped at three months of subscription fees, and excludes any claim arising from a prompt the user wrote. The general counsel asks the AI Governance Lead three questions: Who owns this? What can a competitor do with it? Are we exposed if the underlying training data was infringing? The answers are knowable in 2026, but only if the IP strategy was set before the asset was generated. This lesson is that strategy: U.S. Copyright Office guidance, UK CDPA s.9(3), EU Member-State variation, China's Beijing Internet Court decisions, vendor-by-vendor terms, indemnity provisions to demand, and the operational workflow that documents human creative contribution so AI-assisted works carry defensible copyright.
The 2026 IP Landscape for AI Outputs
Generative AI moved from research demos to default marketing tooling in 24 months. The intellectual-property regime has not kept pace. As of May 2026, there is no globally harmonized rule for the copyrightability of AI-generated outputs. Four jurisdictions are setting the operative precedent that an AI Governance Lead has to navigate.
United States - Copyright Office Continuing Guidance
The U.S. Copyright Office published its three-part report on Copyright and Artificial Intelligence on a staggered schedule:
- Part 1 - Digital Replicas (July 2024). Recommends federal legislation protecting individuals from unauthorized AI-generated digital replicas of their voice or likeness. Not yet enacted as of May 2026; multiple federal NO FAKES Act proposals pending.
- Part 2 - Copyrightability (January 2025). Confirms the long-standing human-authorship requirement. Purely AI-generated outputs are uncopyrightable. AI-assisted works are copyrightable to the extent of the human creative contribution. The Office's case-by-case approach asks whether a human exercised sufficient creative control over the expressive elements of the work.
- Part 3 - Generative AI Training (expected 2026). Will address whether training generative AI on copyrighted works constitutes fair use, and the licensing-market implications. Most-watched of the three.
The judicial backdrop is Thaler v. Perlmutter, in which the D.C. Circuit affirmed the Office's denial of registration for an image generated autonomously by an AI system without human creative input. The case is the precedent floor for the human-authorship requirement in U.S. law. The Office has since registered AI-assisted works (e.g., the Zarya of the Dawn graphic novel for the human-authored text and selection / arrangement, but not the Midjourney-generated images themselves; subsequent registrations have similarly disaggregated human and AI contributions).
Operational implication. In the United States in 2026, an output that the Copyright Office or a federal court treats as purely AI-generated is in the public domain. A competitor can copy it without infringement liability. The defensive move is to ensure every commercial-value AI output carries documented human creative contribution sufficient to qualify the work as AI-assisted rather than AI-only.
United Kingdom - CDPA s.9(3) Computer-Generated Works
The UK's Copyright, Designs and Patents Act 1988 (CDPA) s.9(3) defines authorship of a computer-generated work as "the person by whom the arrangements necessary for the creation of the work are undertaken." The term of protection for such works is 50 years from creation (CDPA s.12(7)), compared to life plus 70 years for human-authored works. The UK is the rare jurisdiction with a specific statutory regime for computer-generated works.
The UK Intellectual Property Office consultation on AI and copyright (initiated 2024, ongoing through 2026) is reviewing whether CDPA s.9(3) should be retained, reformed, or repealed. The consultation also covers the TDM-exception scope (the analogue to the EU's Article 4(3) Copyright Directive opt-out, covered in lesson 037). As of May 2026, the consultation outcome is pending; CDPA s.9(3) remains in force.
Operational implication. In the UK in 2026, an organization producing AI-generated outputs may be able to assert copyright under CDPA s.9(3) as "the person by whom the arrangements necessary for the creation of the work are undertaken", typically the user / deployer rather than the model provider. The protection term is shorter, and the consultation outcome may change the regime. The defensive move is to document the arrangements (prompt design, model selection, post-processing) to support the s.9(3) claim while planning for potential reform.
European Union - Copyright Directive 2019/790 and Member-State Variation
The EU's Copyright Directive (2019/790) harmonizes the text-and-data-mining exceptions (Articles 3 and 4, the opt-out covered in lesson 037 and EU AI Act Article 53(1)(c)). The Directive does not establish a specific copyright regime for AI-generated outputs. The general human-authorship requirement under the InfoSoc Directive and the Court of Justice case law (notably Infopaq and Painer, requiring the author's own intellectual creation) applies, purely AI-generated outputs typically fail that test.
Member-State variation is substantial. France, Germany, Italy, Spain, the Netherlands, and others have each issued national guidance or case law on AI-assisted works in 2024-2026, with broadly converging conclusions that human creative input is required but with differing standards for what suffices. A multi-jurisdictional EU deployment requires per-Member-State legal review.
China - Beijing Internet Court Recognition of AI-Assisted Copyrightability
In Li v. Liu (Beijing Internet Court, November 2023, with subsequent confirmations through 2024-2026), a Chinese court recognized copyright protection for an AI-generated image where the user had exercised sufficient creative input through prompt design, parameter selection, and output curation. The decision is widely cited as the most permissive major-jurisdiction precedent for AI-assisted-work copyrightability. Subsequent Beijing Internet Court decisions and Shanghai-court decisions have broadly aligned with the Li v. Liu approach, though China's lack of binding precedent means each case is decided on its facts.
Operational implication. In China, an AI-assisted output with documented user creative input may carry copyright protection. The contrast with the U.S. position is notable, the same output may be copyrightable in Beijing and uncopyrightable in Washington D.C. depending on how the creative contribution is documented and the court evaluates it.
Ownership Decisions for AI-Generated Marketing Assets
The IP strategy starts with an ownership decision per output category. The four-jurisdiction landscape above means a single rule does not work. The operational default for a 2026 multi-jurisdictional enterprise:
- Prefer AI-assisted over AI-only. Every commercial-value generative output should carry documented human creative contribution sufficient to qualify the work as AI-assisted in U.S. analysis, sufficient to support CDPA s.9(3) claim in the UK, sufficient to meet Infopaq / Painer human-creativity threshold in the EU, and sufficient to align with Beijing Internet Court precedent in China.
- Document the human creative contribution. The documentation typically covers: prompt design (the prompt as written, the iteration history, the creative intent behind the prompt); model and parameter selection (the model choice, the seed, the sampling parameters); selection and curation (the choice among generated outputs, the rationale); post-processing (any human editing, compositing, or refinement of the generated output). The documentation is the evidence base for both the copyright claim and the procurement defense.
- Tag the asset. The asset in the brand library carries metadata identifying the AI tool used, the date of generation, the prompt (or prompt summary), the human contributor, and the human-contribution category. The metadata is the operational analogue of the copyright registration package.
- Disaggregate for registration where applicable. For U.S. registration, the human-authored elements (text, selection, arrangement, post-processing) can be separately registered; the AI-generated elements remain unregistered. The disaggregation pattern was set in Zarya of the Dawn (Midjourney images unregistered; text and arrangement registered) and confirmed in subsequent registrations.
For low-value outputs (internal documentation, throwaway draft images, test content), the documentation overhead may not be justified. The triage rule: any output that ends up in customer-facing material, in a product, in marketing, or in trademark / patent / regulatory submissions must carry the human-contribution documentation.
Vendor Terms and Customer-Vendor Allocation
Beyond the public-law copyrightability question, the contractual allocation between customer and vendor determines who can use the output, who indemnifies whom, and what carve-outs apply. The 2026 vendor landscape:
Output Ownership in Vendor Terms
- OpenAI (ChatGPT, DALL-E, Sora). Customer owns the output, subject to compliance with the Terms of Use. OpenAI assigns rights to the customer to the extent assignable. Enterprise tier provides additional protections.
- Anthropic (Claude). Customer owns the output. Anthropic does not claim rights in customer outputs. Subject to Acceptable Use Policy.
- Google (Gemini, Imagen, Vertex AI). Customer owns outputs. Vertex AI Enterprise terms include additional commercial-use protections and IP indemnity (see below).
- Microsoft (Copilot, Azure OpenAI). Customer owns outputs. Microsoft provides the Copyright Commitment for paid tiers (see below).
- Adobe (Firefly). Customer can use commercially with caveats around the training-data composition (Firefly was trained on Adobe Stock + licensed + public-domain content, designed to be commercial-safe). Adobe provides IP indemnity for Firefly outputs in enterprise tiers.
- Midjourney. Tiered ownership, paid tiers grant customer ownership of outputs; free / community tiers grant a limited license with public-display obligations.
- Stability AI. Open-source models (Stable Diffusion family) carry permissive licenses on outputs; paid / enterprise tiers add commercial-use commitments and limited indemnity.
- Runway, Pika, Sora. Generally customer-owned outputs on paid tiers; review per-vendor terms for any retained rights.
- ElevenLabs, Suno (audio). Customer-owned outputs on commercial tiers; voice-cloning has additional restrictions tied to consent and right-of-publicity.
The output-ownership clause is necessary but not sufficient. It allocates the contractual rights between the parties but does not establish copyrightability under public law. A customer who "owns" an AI-only output under contract still cannot enforce copyright in the United States against a third party who copies it.
Vendor IP Indemnity Commitments
The high-stakes question for enterprise procurement is the IP infringement indemnity. The major-vendor 2026 landscape:
- Microsoft Copilot Copyright Commitment. Microsoft defends and pays damages for paid customers of Copilot products (including GitHub Copilot, M365 Copilot, Azure OpenAI Service) against third-party IP claims, subject to customer use of the safety controls and guardrails. Covers IP infringement claims arising from the AI output.
- Adobe IP Indemnity (Firefly). Adobe defends and pays damages for enterprise customers against third-party IP claims arising from Firefly outputs, predicated on Adobe's training-data composition (Adobe Stock + licensed + public-domain).
- Google Vertex AI IP Indemnity. Google defends and pays damages for enterprise customers against third-party IP claims arising from Vertex AI generative outputs and training data, subject to terms.
- OpenAI Copyright Shield (ChatGPT Enterprise, API). OpenAI defends and pays customer costs for IP claims arising from output. Coverage applies to ChatGPT Enterprise, ChatGPT Team, and certain API tiers.
- Anthropic. Anthropic provides defense and damages indemnity for IP infringement claims arising from Claude output for commercial-tier customers (Claude Enterprise, API), subject to terms.
- Smaller vendors / open-source. Generally no indemnity, or defense-cost only with low caps. Stability AI, Midjourney free tier, and many smaller vendors do not provide full damages indemnity.
Defense-Cost-Only vs. Damages Indemnity
The distinction is critical. Defense-cost-only indemnity covers the attorney fees and litigation costs of defending a claim but does not pay any settlement or judgment damages. Damages indemnity covers both. A defense-cost-only indemnity for a high-stakes IP infringement claim can leave the customer with millions in exposure if the claim succeeds. The major-vendor commitments above are generally full defense-plus-damages; many smaller and open-source vendors are defense-cost only or capped at modest amounts.
Operational rule: every generative-content vendor contract above a defined threshold (e.g., $50K annual spend, or any deployment producing customer-facing content) must include full defense-plus-damages indemnity. Defense-cost-only or capped-damages indemnity is acceptable only with explicit risk acceptance from legal and the audit committee.
Reasonable Indemnity Carve-Outs
Vendor indemnities universally carve out certain customer behaviors:
- Intentional misuse. Prompts designed to elicit copyrighted material (e.g., "generate the cover of the Beatles' Abbey Road album"). The carve-out is reasonable; the customer who intentionally prompts infringing content cannot expect indemnification.
- Specific prompts. Prompts that identify specific copyrighted works, characters, or trademarks by name. The carve-out narrows what the customer can prompt without losing indemnity coverage.
- Protected-content prompts. Prompts that include or reference copyrighted material as input (e.g., asking the model to "continue this poem" with copyrighted text). The carve-out can extend to outputs where the customer's input prompt itself triggers infringement.
- Failure to use safety controls. Customer disabling content filters, watermarking, or other vendor-provided guardrails.
- Modifications to output. Customer editing the output to introduce infringing content; vendor not liable for customer-introduced changes.
- Use beyond license scope. Customer using output outside the licensed use case (e.g., training a competing model on vendor outputs).
The carve-outs are negotiable in enterprise procurement. The procurement-defense workflow should review each carve-out against the customer's expected use patterns and either accept, narrow, or negotiate alternative protection (e.g., indemnity-mirror clauses in customer-facing terms).
Use-Case Strategy by Output Category
The IP strategy varies by output category because the risk profile varies:
- Marketing creative (images, video, audio). Article 50(4) deepfake disclosure where applicable; full defense-plus-damages indemnity from vendor; AI-assisted curation with documented human contribution; C2PA / SynthID / IPTC marking under Article 50(2) (lesson on Article 50 covers the marking obligations); legal review on any third-party-likeness or trademark-style imagery; brand-library metadata tagging.
- Customer-service content (chat responses, FAQs, support articles). Confabulation / hallucination risk is the dominant concern; human-review required before publication; AI Act Article 50(1) chatbot disclosure where deployed in real-time interaction; IP exposure typically lower for ephemeral chat responses but elevated for published support articles.
- Internal documentation (process docs, meeting summaries, internal training). Lower external IP exposure; human-contribution documentation still useful for any document that might later be published; data-confidentiality / vendor-training implications must be evaluated separately.
- Software code (GitHub Copilot, Cursor, Codeium, Continue.dev). Same human-authorship considerations as written content; additional license / training-data infringement risk because of GPL / copyleft contamination concerns; Microsoft Copilot Copyright Commitment is the main vendor shield (with safety-control compliance required); customer-side licensing review for any code deployed in customer-facing or open-source products.
- Research / analysis (literature review, market analysis, summarization). Generally low IP exposure for derivative analysis; quoting / citing source materials follows normal copyright rules; AI-generated analysis is uncopyrightable in the U.S. but the underlying human-authored analysis (research questions, conclusions, recommendations) carries human authorship.
- Product copy / UX text (button labels, error messages, onboarding flows). Generally low IP exposure (short functional text is often non-copyrightable regardless); human-review for brand-voice consistency; trademark considerations on any taglines or product names.
Indemnity Provisions to Demand in Vendor Contracts
The procurement-defense checklist for any generative-AI vendor contract above the threshold:
- IP infringement defense. Vendor defends the customer against third-party IP claims arising from the AI output. Defense includes attorney fees, court costs, expert fees, and other reasonable defense costs.
- IP infringement damages. Vendor pays settlement amounts and judgment damages arising from the IP claim. Coverage should be uncapped or at minimum capped at a multiple of annual contract value sufficient to absorb realistic claim outcomes.
- Reasonable carve-outs only. The carve-outs (intentional misuse, specific-prompt requests, protected-content prompts, safety-control disablement, customer-introduced modifications, use beyond license scope) should be narrowly drafted and exhaustively listed. No catch-all "vendor not liable for any claim involving the output" language.
- Procedural cooperation. Customer notifies vendor of any claim promptly. Vendor controls the defense subject to customer consent on settlement. Customer cooperates in good faith.
- Settlement authority. Vendor cannot settle a claim without customer consent if the settlement imposes obligations on the customer beyond payment by the vendor (e.g., admissions, public statements, future-use restrictions).
- Coverage scope. Indemnity covers output from the product, output used in customer's normal-course commercial operations, and (where vendor agrees) outputs incorporated into customer products.
- Sub-limit transparency. Any sub-limits on damages (e.g., per-claim cap, per-year aggregate cap) must be explicit and reviewed against risk acceptance.
- Term and survival. Indemnity survives termination of the agreement for outputs generated during the term.
Pending Litigation Shaping 2026 Precedent
The case landscape that an AI Governance Lead should track quarterly:
- The New York Times Company v. Microsoft and OpenAI. Filed December 2023. Alleges copyright infringement in training and output reproduction. Discovery and motion practice continuing through 2026. The case is the most-watched single matter for the fair-use-in-training question that Copyright Office Part 3 will address.
- Authors Guild et al. v. OpenAI. Filed 2023. Class action by author plaintiffs (George R.R. Martin, John Grisham, others) over training-data use of copyrighted novels. Consolidated with other author-plaintiff cases.
- Getty Images v. Stability AI. Parallel U.S. and UK proceedings. Alleges copyright infringement and trademark infringement in training and output. The UK case has a 2025-2026 trial schedule; outcome will shape UK precedent.
- Music-publisher class actions. Multiple actions against generative-music vendors and providers including Suno, Udio. Alleges training-data infringement and output reproduction of copyrighted compositions. The music-publisher landscape (Universal, Sony, Warner) is highly litigious and has historically driven major precedent (e.g., the 1990s sampling cases).
- Artist class actions against image generators. Andersen et al. v. Stability AI, Midjourney, DeviantArt, Runway. Class action by visual artists alleging training-data infringement and stylistic replication. Motion practice 2024-2026.
- Concord Music v. Anthropic. Alleges training-data use of copyrighted lyrics. Settled in part with consent decree on certain remediation; broader claims continuing.
The case outcomes through 2026-2027 will reshape the vendor-indemnity landscape, successful plaintiff claims will increase vendor exposure and may narrow indemnity terms; successful defendant defenses (e.g., fair use) will preserve current vendor terms.
Regulatory Cross-Walks
The IP strategy integrates with the broader EU AI Act and certification framework:
- EU AI Act Article 50(2) and 50(4). Machine-readable marking of synthetic content (50(2), accelerated to Dec 2, 2026 under Omnibus VII) and deepfake disclosure (50(4)) operate alongside the IP analysis. Marking does not establish copyright; disclosure does not extinguish IP claims.
- EU AI Act Article 53(1)(c). GPAI provider obligation to implement a copyright policy and respect TDM opt-outs. Covered in detail in lesson 037.
- EU Copyright Directive 2019/790 Articles 3 and 4. Text-and-data-mining exceptions including the rightsholder opt-out under Article 4(3) for commercial use. The TDM opt-out is the upstream IP-protection mechanism; the AI-output-copyright analysis in this lesson is the downstream IP-protection mechanism.
- U.S. Copyright Office Part 2 (Copyrightability). Foundational guidance for U.S. ownership analysis. Part 3 (Generative AI Training) will address training fair use.
- UK CDPA s.9(3). Computer-generated works regime, under review through the UK IPO consultation.
- GPAI Code of Practice Copyright Chapter. The signatory-vendor commitments on TDM opt-out compliance, training-data transparency, and copyright-policy publication. Microsoft, Google, Anthropic, OpenAI, Meta, Mistral, Amazon all signatory.
- ISO 42001 A.7 (Data) and A.10 (Information for Interested Parties). The AIMS controls covering data-use governance and downstream-deployer information; the IP strategy integrates with the AIMS evidence stack.
- NIST AI RMF 1.0 / AI 600-1. AI 600-1 Risk 7 (Intellectual Property) explicitly covers training-data and output IP risk; the NIST framework integrates with the U.S. IP analysis.
Six Common AI-Output IP Strategy Mistakes
Mistake 1 - Assuming AI-Only Outputs Are Copyrightable
In the United States, AI-only outputs without sufficient human creative contribution are uncopyrightable. The Thaler v. Perlmutter precedent and the Copyright Office Part 2 guidance confirm. A marketing campaign built on "vendor owns it, we own it under contract, therefore we have copyright" reasoning has no enforceable copyright claim against a competitor who copies the asset.
Mistake 2 - Missing Human-Contribution Documentation
The human-contribution documentation is the evidence base for both the copyright claim and the procurement-defense workflow. An AI-assisted output without documented human creative input is operationally indistinguishable from an AI-only output. Default to documentation for any commercial-value output.
Mistake 3 - Accepting Vendor Terms Without Indemnity Review
Off-the-shelf vendor terms often include defense-cost-only or capped-damages indemnity, broad carve-outs, and unilateral settlement authority. The procurement-defense workflow must review and negotiate every clause; full defense-plus-damages with narrowly-drafted carve-outs is the operational target.
Mistake 4 - Over-Relying on Vendor Indemnity
Vendor indemnity is necessary but not sufficient. Indemnity does not extinguish the harm to brand and customer relationships from an IP claim; it does not address the public-law copyrightability question (which the customer must defend separately for any enforcement); it does not cover the carve-outs (which can be invoked in disputed claims). The customer must run its own IP-strategy program, not delegate to the vendor.
Mistake 5 - Missing Pending-Litigation Tracking
The case landscape is shifting quarterly. A program that set vendor terms in 2024 based on the then-current case posture may have terms that no longer match the 2026 precedent. Quarterly tracking of the major cases (NYT v. OpenAI, Getty v. Stability, Authors Guild, music-publisher actions) and proactive vendor-contract refresh is operational.
Mistake 6 - Static IP Policy
The IP regime is in active development across all four major jurisdictions. The U.S. Copyright Office Part 3 (2026), the UK IPO consultation outcome (2026-2027), the EU Member-State precedent development, and the China judicial trajectory all shift the operational defaults. The IP policy must be reviewed and refreshed at least annually with on-event refresh on major developments.
Key Takeaways
- The 2026 IP landscape is jurisdiction-specific. U.S. requires human authorship (Copyright Office Part 2; Thaler v. Perlmutter); UK has CDPA s.9(3) computer-generated-works regime (under review); EU varies by Member State on top of the harmonized TDM framework; China's Beijing Internet Court recognizes AI-assisted copyrightability with documented human input.
- U.S. Copyright Office three-part report. Part 1 (Digital Replicas, Jul 2024); Part 2 (Copyrightability, Jan 2025); Part 3 (Generative AI Training, expected 2026). Part 2 confirms human-authorship requirement; AI-assisted works copyrightable to extent of human creative contribution; AI-only outputs uncopyrightable.
- Prefer AI-assisted over AI-only. Every commercial-value output should carry documented human creative contribution (prompt design, model selection, curation, post-processing). The documentation is the evidence base for copyrightability across all four jurisdictions.
- Output ownership ≠ copyrightability. Vendor contractual grant of output ownership allocates the contract rights between the parties but does not establish public-law copyright. A customer who "owns" an AI-only output under contract still has no enforceable copyright in the U.S.
- Vendor IP indemnity varies materially. Microsoft Copilot Copyright Commitment, Adobe IP Indemnity (Firefly), Google Vertex AI Indemnity, OpenAI Copyright Shield, Anthropic indemnity, full defense-plus-damages typically only on enterprise/paid tiers with safety-control compliance.
- Defense-cost-only vs. damages distinction is critical. Demand full defense-plus-damages for any vendor above the procurement threshold. Defense-cost-only indemnity is risk-acceptance only.
- Carve-outs are negotiable. Intentional misuse, specific-prompt requests, safety-control disablement carve-outs are reasonable; catch-all "vendor not liable for any claim involving the output" language is not.
- Use-case strategy varies. Marketing creative (Article 50(4) + indemnity + documentation); customer-service content (confabulation risk + human review); internal docs (lower exposure + still document); software code (Microsoft Copilot Copyright Commitment + license-contamination review).
- Pending litigation reshapes the landscape. Track NYT v. OpenAI, Authors Guild v. OpenAI, Getty v. Stability, music-publisher actions, artist class actions, Concord Music v. Anthropic. Quarterly review with vendor-contract refresh triggers.
- Cross-walks span Articles 50(2)/(4), 53(1)(c), Copyright Directive, U.S. Copyright Office, UK CDPA s.9(3), GPAI Code Copyright chapter, ISO 42001 A.7/A.10, NIST AI 600-1 Risk 7. The IP strategy integrates with the broader AI governance program.
Skill.re