AI for Designers (UX, Product, Brand)
Strategic · M17 · lesson 17 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The IP Risk Register for a Design Org
📖
now learning

The IP Risk Register for a Design Org

15 min

Somewhere in your asset library right now there is a hero image a designer generated in Midjourney eight months ago, dropped into a client deck, and forgot about. You do not know which prompt produced it, you do not know whether the model leaned on a copyrighted character to get there, and you do not know whether your contract with that client says you indemnify them if it turns out to infringe. Multiply that one asset by the thousand things your team has generated since, and you have the actual shape of intellectual-property risk on an AI-augmented design org: not one dramatic lawsuit, but a thousand small unlogged exposures, none of them individually alarming, all of them adding up to a number nobody has ever totaled. This lesson gives you the instrument that totals it - an IP Risk Register - and the team policy that keeps the number from growing. It is the first thing you build in Risk Management as a Design Strategist, because every other risk in this chapter is downstream of "do we even own what we ship?"

Why IP Is the Risk Leaders Underweight

Ask a design leader to name their biggest AI risk and most will say "quality" or "the team falling behind." Almost none say "intellectual property," and that is precisely why it is dangerous. Quality failures are visible - a bad mock gets caught in review, a broken flow generates support tickets, and the feedback loop is fast enough to manage. IP failures are invisible until they are catastrophic. An infringing asset can sit in production for a year doing no harm at all, generating no signal, right up until a rights-holder's lawyer sends a letter, at which point the cost is not a re-design, it is legal fees, a forced recall of every surface the asset touched, a damaged client relationship, and potentially an indemnification claim that lands on your company's balance sheet rather than the client's.

The asymmetry is the whole problem. IP risk has a low probability per asset and a high cost per incident, and human attention is terrible at that combination. We discount things that have never happened to us, and most design teams have never had an IP incident, so they reason - incorrectly - that they never will. But the base rate changed in 2025. When Disney and Universal, two of the most litigious rights-holders on earth, filed suit against an AI image model, they signaled that the legal industry now considers generated-asset infringement worth pursuing at scale. The question stopped being "could this ever be a problem" and became "when does the enforcement wave reach a company my size." A risk register is how you answer that question with a number instead of a shrug.

There is a second reason leaders underweight it: IP feels like legal's job, not design's. It is not. Legal can write the contract language and defend the claim, but legal cannot see which tool a designer reached for on a Tuesday, cannot tell a generated asset from a hand-made one in your library, and cannot know that the "stock photo" in the launch deck was actually a Firefly composite. The exposure is created at the point of generation, inside the design workflow, by design decisions. That makes the design strategist the only person positioned to catalog it. You are not doing legal's job; you are giving legal the inventory they cannot produce themselves.

The Four Exposure Categories Every AI Design Stack Carries

An IP risk register is only useful if it is built from the actual ways an AI design stack creates exposure, not a generic legal checklist. There are four categories, and they fail differently, so each needs its own column. Catalog all four and you have a complete picture; skip one and it is the one that bites you.

Generated Assets and the Ownership Question

The first exposure is the one everyone thinks of: the images, illustrations, icons, and compositions your team generates and ships. Two distinct risks live here, and teams routinely conflate them. The first is output ownership - can you even claim copyright in a purely AI-generated image? Under current US Copyright Office guidance, a wholly machine-generated image has no human authorship and therefore no copyright protection, which means a competitor can copy your generated brand asset and you have no standing to stop them. The second is output infringement - does the generated image reproduce protectable elements of someone else's work, because the model was trained on it and reached for it? These are opposite-facing risks: one is about what you cannot protect, the other about what you might be violating. Your register needs to flag both, per asset class.

The practical move is to classify every generated-asset workflow by where it sits on a risk gradient. A purely generative hero image for a marketing campaign is high exposure on both axes. An AI-assisted vectorization of a logo the client already owns is low exposure, because the underlying IP is theirs and the AI did mechanical work. An AI-upscaled version of a licensed stock photo sits in between. The register's job is to make these distinctions explicit so a designer can look up "am I allowed to ship this for a client" and get an answer that is not a guess.

Training-Data Provenance and What the Model Was Built On

The second exposure sits one layer below the asset: what the model itself was trained on, which you usually cannot see and which can taint everything that comes out of it. This is the layer the 2025-2026 litigation actually targets. The plaintiffs are not primarily arguing that a specific output infringes; they are arguing that the act of training on copyrighted works without license was itself infringement, and that the model is therefore a machine built to reproduce their IP. You inherit a fraction of that argument every time you use a model whose training set is contested.

This is why the Adobe Firefly versus Midjourney distinction matters to a design org in concrete budget terms, not abstract ethics terms. Adobe trains Firefly predominantly on licensed and owned content and offers commercial indemnification on paid Creative Cloud plans, which means Adobe is contractually agreeing to stand behind your output if a training-data claim arrives. Midjourney, Stable Diffusion, and FLUX make no such promise; their training sets are contested and the exposure flows straight through to you. The register has to record, per tool, whether training-data risk is indemnified by the vendor or retained by you, because that single fact determines whether a given workflow is a manageable risk or an uninsured bet.

Indemnification Gaps and Who Actually Holds the Bag

The third exposure is the gap between what you assume is covered and what the terms of service actually say. Designers reach for the tool that produces the best image, not the tool with the best indemnification, and they almost never read the terms. So the register's third column forces the question every leader avoids: if a claim arrives on this asset, who pays? The answers form a chain - the vendor (if they indemnify and the use qualified), your company, or, worst of all, the client you passed the risk to without telling them. Indemnification is also conditional in ways teams miss: it usually requires you to have used the paid tier, not modified the output beyond a threshold, and not combined it with prompts that reference protected IP. A designer who types "in the style of a famous studio" into an indemnified tool can void the indemnification with that one prompt, and nobody will know until it matters.

Client Deliverables and the Contract You Already Signed

The fourth and most expensive exposure is contractual: what you promised clients about the work you deliver. Most agency and contractor agreements contain a representation that the deliverables are original and do not infringe third-party rights, and an indemnification clause where you agree to cover the client if that representation turns out to be false. Those clauses were written before generative AI and they almost never carve out AI-generated content. Which means that every time a designer ships a generated asset into a client deliverable under one of those contracts, your company has silently accepted unlimited liability for a risk it cannot fully assess. This is the category that can sink a small studio, and it is the one least likely to appear in a technical risk discussion, because it lives in the contract drawer, not the Figma file. The register's job is to surface it so legal can renegotiate the AI carve-outs before, not after, the claim.

The Disney / Universal / Warner Bros. Case, in Two Sentences

Every brand designer on your team should be able to summarize this case in two sentences, because it is the single most cited piece of evidence that generated-asset risk is real and being enforced. Here is the case material, factual and current as of mid-2026.

Disney and Universal filed suit against Midjourney in June 2025, alleging that the model was trained on and reproduces their copyrighted characters without license, and Warner Bros. Discovery joined with its own claims in September 2025; the actions were consolidated. As of mid-2026 the parties are not in active discovery but in private mediation under court-ordered alternative dispute resolution, with a court-set deadline of August 19, 2026 to reach resolution before litigation proceeds.

Those are the two sentences. Notice what they do and do not establish. They do not establish that using Midjourney is illegal, that a court has ruled against the model, or that your team is currently breaking the law. What they establish is that the largest rights-holders in the world consider generated-asset infringement worth their litigation budget, that the dispute is serious enough to be in mandated mediation rather than dismissed, and that the legal weather has shifted from "theoretical" to "active." A designer who can state this cleanly sounds informed; one who either ignores it or catastrophizes it ("Midjourney is illegal now") loses credibility in the room. The register turns this case from background anxiety into a calibrated input: it is a reason to record training-data exposure, not a reason to ban a tool.

The litigation does not tell you to stop using AI. It tells you to know, for every asset you ship, who would pay if a letter arrived. That is the entire purpose of the register.

Building the One-Page Risk Register

The artifact this lesson exists to produce is a one-page IP Risk Register: a single table an executive can read in two minutes and a designer can look up before they ship. One page is a deliberate constraint. A twelve-page legal memo gets filed and never opened; a one-page register gets pinned to the wall and consulted. The discipline of fitting it on a page also forces you to rank exposures rather than list them, which is the whole point of a register over an inventory.

The register has one row per workflow-and-tool combination - not per asset, which would be unmanageable, but per recurring way your team generates IP. "Marketing hero images in Midjourney," "logo vectorization in Recraft," "stock-photo composites in Photoroom," "in-product illustration in Firefly," and so on. Each row carries the columns the four exposure categories demand.

The Columns That Make It Decision-Grade

Workflow and tool. The specific recurring use and the model behind it, because risk attaches to the tool, not the abstraction "AI."

Exposure type. Which of the four categories apply - output ownership, output infringement, training-data, indemnification gap, client-contract - usually more than one.

Indemnification status. Vendor-indemnified, conditionally indemnified, or retained-by-us, with the condition named (paid tier, no protected-IP prompts). This is the column legal cares about most.

Likelihood and impact. A simple low/medium/high on each, multiplied into a risk score so the page self-sorts. A high-impact, low-likelihood row (a generated character that resembles a protected one) can outrank a medium/medium row, which is exactly the prioritization human intuition gets wrong.

Mitigation and owner. The specific control that lowers the score - "use Firefly for client deliverables," "require provenance log entry," "legal carve-out in MSA" - and the named person accountable for it. A risk with no owner is a risk nobody is managing.

The register is not a static document. It is reviewed quarterly, because the tool landscape, the vendor terms, and the legal weather all move. When the August 2026 mediation deadline resolves one way or another, the training-data row's likelihood score moves, and the register should move with it. A register that is not dated and re-dated is a register nobody trusts.

From Register to Team Policy

A register that only the strategist reads changes nothing. The register's purpose is to drive a small number of clear team policies that move the high-score rows down. Resist the urge to write a long policy document; the teams that actually comply have three or four rules a designer can hold in their head, not a wiki nobody reads.

The first policy is the tool-tier rule: for any deliverable that goes to a client or ships to production under a contract with an IP representation, use only tools that carry commercial indemnification - which in practice in 2026 means Firefly on a paid plan for image generation - unless legal has explicitly cleared an exception. Exploratory and internal work can use the full toolbox; the constraint kicks in at the contract boundary. This single rule retires most of the client-deliverable exposure, the most expensive category, at the cost of slightly less range on the deliverables that matter most.

The second policy is mandatory provenance logging, which connects this lesson to the provenance work from L1 and L3. Every shipped generated asset gets a log entry - tool, model, prompt, date, indemnification status - so that if a claim ever arrives, you can answer "which asset, made how, under what terms" in minutes instead of forensically reconstructing a year of forgotten work. The log is also what makes the register accurate over time, because it is the data source the quarterly review reads from. Without provenance, the register is built on memory, and memory is exactly the thing that fails when a letter arrives eleven months after the asset shipped.

The third policy is the prompt-hygiene rule: no prompts that reference protected IP by name or studio style on any asset destined for a deliverable, because those prompts both raise infringement likelihood and void indemnification. This is the cheapest control on the register and the one most often violated, because "make it look like that famous franchise" is genuinely how designers think out loud. The policy does not ban the thought; it bans shipping the result of it under your company's name.

The fourth, owned by you in partnership with legal, is the contract carve-out: a standard clause in your MSAs that addresses AI-generated content explicitly - either disclosing its use and limiting the IP representation accordingly, or specifying which tools were used and on what indemnification terms. This is the highest-leverage policy because it operates on the most expensive exposure, and it is the one a design strategist can initiate but cannot complete alone. Your job is to bring legal the register so they understand what they are carving out for.

Presenting the Register to Leadership

The register is an executive artifact, which means how you present it determines whether it gets resourced. The failure mode is presenting it as a wall of red that reads as "design is a liability," which invites exactly the wrong response - a ban on AI tools that kneecaps the team's velocity without actually managing the risk, because the shadow-IT use simply moves off the books. The framing that works is the opposite: "here is the exposure we are carrying today, here is what it would cost if it materialized, and here are four cheap controls that move us from uninsured to managed without slowing the team down."

Lead with the total, not the rows. An executive does not want to read fifteen workflow rows; they want one sentence - "we have three high-exposure workflows feeding client deliverables under contracts with no AI carve-out, representing the bulk of our retained IP risk, and the fix is a tool-tier rule plus a contract clause, both of which we can ship this quarter." That sentence is fundable. The fifteen rows are the appendix that backs it up when someone asks. You are translating a design-workflow reality into the language of managed risk, which is the language the org respects, and the register is the translation layer.

Frame the controls as risk reduction with a known cost, the way an insurance decision is framed. The tool-tier rule costs the team some range on client work; the provenance log costs a few minutes per asset; the contract carve-out costs a legal review cycle. Against those known costs you are buying down a low-probability, high-cost tail risk that, if it lands, costs orders of magnitude more. Put that way, the register is not a confession of a problem; it is a leader doing exactly what leaders are supposed to do with a risk they can see, which is to price it and decide deliberately how much of it to carry.

Putting It to Work This Quarter

Build the first version of the register this week, badly and incompletely, from memory, in one sitting. The instinct is to wait until you have perfect provenance data, but a rough register today beats a perfect one next quarter, because the act of building it surfaces the workflows you forgot you had. List every recurring way your team generates assets, tag each with its exposure types, make a fast low/medium/high guess on likelihood and impact, and you will have something genuinely useful within an hour. The high-score rows will be obvious immediately, and they are where you start.

Then do three things. Take the register to legal and ask the one question that matters most: do our client contracts carve out AI-generated content, and if not, what is our actual exposure. Stand up the provenance log if you do not have one, so next quarter's register is built on data instead of memory. And write the four short policies as a single one-page companion to the register, so a designer who reads the register also reads what to do about it. You will know it is working when a designer pings you before shipping a client asset to ask which tool is cleared - that is the register having moved out of your head and into the team's default behavior, which is the only place a risk control actually reduces risk.

Key Takeaways

  • IP risk on an AI design stack is low-probability, high-cost, and invisible until catastrophic - exactly the profile human attention underweights. A register exists to total an exposure nobody has otherwise counted and turn a shrug into a number leaders can act on.
  • There are four distinct exposure categories, and they fail differently: generated assets (output ownership and output infringement), training-data provenance, indemnification gaps, and client-contract representations. The last is the most expensive and the least likely to surface in a technical risk discussion because it lives in the contract drawer.
  • The Disney and Universal suit against Midjourney (June 2025), joined by Warner Bros. Discovery (September 2025) and consolidated, is in court-ordered mediation with an August 19, 2026 deadline. It does not make AI illegal; it establishes that generated-asset infringement is now actively enforced, which is a reason to record training-data exposure, not ban a tool.
  • The Firefly-versus-Midjourney distinction is a budget fact, not an ethics one: Firefly's licensed training plus paid-plan commercial indemnification moves risk to the vendor; Midjourney, Stable Diffusion, and FLUX retain it with you.
  • The artifact is a one-page register, one row per workflow-and-tool combination, with columns for exposure type, indemnification status, likelihood-times-impact score, and a named owner. One page forces ranking over listing, and a dated quarterly review keeps it honest as the legal weather moves.
  • The register drives four short policies: a tool-tier rule (indemnified tools only at the contract boundary), mandatory provenance logging, prompt hygiene (no protected-IP references on deliverables), and an MSA AI carve-out you initiate with legal. Present it as priced, manageable risk reduction - not a wall of red that invites a counterproductive ban.