← All posts

The Archibal Team

Who is liable for AI creative work? A practical guide for agencies

Liability for AI creative work is layered and unsettled. The single biggest thing protecting your agency is a contemporaneous record of what actually happened - which model, on which plan, what a human contributed, who approved it.

Nobody hands out a clean answer to this question, because the law is still catching up. But agencies cannot wait for the law to settle before taking on client work. So here is the most accurate answer available right now: liability for AI creative work is layered, it shifts depending on how you use the tools, and the single biggest thing you can do to protect your agency is document what actually happened.

The short version before the detail

  • Pure AI outputs - no meaningful human creative input - are almost certainly not copyright-protectable in the US, the EU, or the UK.
  • You probably own the outputs contractually, but contractual ownership and legal enforceability are different things.
  • Vendor indemnity (the "copyright shield") is real but narrow, and it does not apply unless you are on an enterprise or API plan.
  • Under the EU AI Act, your agency may be a deployer with its own transparency and disclosure obligations, separate from the model vendor's.
  • The strongest defence - to clients, platforms, or regulators - is not a policy document. It is a contemporaneous record of what your team contributed, which model was used, on which plan, and who approved the result.

Who actually owns AI-generated outputs?

The first question agency principals ask is usually about ownership: does the client own the work? Does the agency? Does OpenAI?

The contractual answer is mostly clear. Most major providers - OpenAI, Anthropic, Google, Adobe, Midjourney on paid plans - assign output ownership to the user or at least disclaim any claim to it. OpenAI's terms, for instance, assign the company's interest in outputs to you "where allowed by law." Anthropic does the same for commercial customers. Google Gemini does not claim ownership and retains only an operational licence.

The legal answer is more uncomfortable. As of 2025, the US Copyright Office confirmed that AI-generated content can only attract copyright protection where a human author has contributed sufficient creative expression. Prompts alone are not enough. The Office specifically noted that prompts may describe the desired result but the AI system determines how those instructions are expressed - and that determination belongs to the machine, not the human. The D.C. Circuit confirmed the same year that the Copyright Act requires human authorship and does not permit registration for works generated autonomously by AI.

In Germany, a Munich court reached the same conclusion in early 2026: AI-generated logos were not works of art for copyright purposes because they lacked personal intellectual creativity. The court noted that protection may be available via trademark and design law - but those require separate registration, not just creation.

The practical consequence for agencies: if you generate an asset by prompting a model and passing the output to a client without meaningful human editing, the agency may have contractual rights to the output but no enforceable copyright to back them up. Anyone could, in theory, use the same or similar outputs freely. That is a real client risk you need to address in your SOW language.

What does create copyright protection is meaningful human contribution after the prompt: substantial editing, creative selection and arrangement, modification of expressive elements, or incorporation into a larger human-authored work. The Polsinelli analysis from May 2026 puts it well: "a company's future position may depend less on broad claims that AI was merely a 'tool' and more on whether it can show, with contemporaneous evidence, what a human actually contributed to the authorship of the copyrighted work."

In other words: own your edits, and be able to prove them.

What the vendor copyright shields actually cover (and don't)

OpenAI, Anthropic, Microsoft, Google, Adobe, Shutterstock, and IBM have all introduced some form of IP indemnification for enterprise or commercial-tier users. The programs differ in detail, but the broad structure is the same: the vendor will step in and pay legal costs if you face a third-party copyright infringement claim arising from your authorised use of their outputs.

That sounds comprehensive. It is not.

OpenAI's Copyright Shield covers ChatGPT Enterprise and the API. It does not cover free ChatGPT or ChatGPT Plus. The indemnity also does not apply if you combined outputs with third-party content, if you fine-tuned or modified the model, if the claim involves your input data, or if the infringement arose from your specific customer application rather than the base model output.

Anthropic's commercial indemnity, introduced at the start of 2024, covers enterprise API customers against claims arising from "authorised use of our services or their outputs." It excludes modifications made by the customer to outputs, combinations with non-Anthropic technology, and claims arising from the customer's prompts.

Google offers SaaS-style disclaimers across Workspace and Gemini API tiers but no specific output indemnity programme equivalent to OpenAI's or Anthropic's at the consumer level. Microsoft's enterprise coverage is more robust through its commercial M365/Copilot agreements but is similarly narrow in practice.

For agencies, the critical implication is this: if your team is using ChatGPT Plus, Midjourney on a standard plan, Stability AI with default settings, or any free-tier tool, you are unprotected by vendor indemnity. If a client or third party brings a copyright claim, your agency is on its own. The Financial Times noted in 2024 that even the cloud giants' indemnity pledges were narrow, and that assessment remains accurate.

Even for teams on enterprise plans, the indemnity only runs from vendor to agency. It does not automatically flow to clients unless your own agency contract is explicit. That means your MSA needs to address whether and how that downstream protection is passed through, and under what conditions.

What the EU AI Act adds: you may be a deployer

Most liability conversations focus on copyright. The EU AI Act introduces a separate obligation that is becoming just as important for agencies: the deployer duty under Article 50.

Article 50 becomes applicable on 2 August 2026. In plain terms, it says:

  • Providers of generative AI systems must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
  • Deployers who distribute deepfakes, certain AI-generated images, audio, or video to EU audiences must disclose that the content has been artificially generated or manipulated.
  • Deployers who publish AI-generated text on matters of public interest must disclose the AI origin, unless the text has undergone a process of human review and a natural or legal person holds editorial responsibility for it.

For agencies, the key word is deployer. You do not need to be building the model. You need only to be the organisation using the model in a real workflow and placing the output into the EU market. A London agency producing AI campaign imagery for a German launch, or a New York studio generating synthetic voiceover for a French broadcast, is very likely a deployer under this framework.

The editorial exemption in Article 50(4) for AI-generated text matters for agencies producing editorial-style content: if a human reviews the text and a person holds editorial responsibility for publication, the disclosure obligation does not apply. But the exemption only works if you can actually show the editorial process. "A human looked at it quickly" is a weak defence. A timestamped review record with a named approver is a strong one. That distinction is not academic - the draft guidelines published for consultation in May 2026 make clear that deployers relying on the editorial exemption must retain specific documentation of their process.

The Code of Practice on marking and labelling AI-generated content - being finalised by the EU AI Office through June 2026 - signals a clear direction: multi-layered marking using embedded metadata, watermarking, and fingerprinting will be the technical baseline. No single technique is sufficient on its own.

What goes in your contracts

The liability exposure is real, but much of it is contractually manageable. Five clauses every agency should review in its MSAs and SOWs before shipping AI-assisted work:

1. AI disclosure and acknowledgement. State explicitly that AI-assisted methods may be used in production. Define which tools or model families are permitted (e.g. "commercially licensed AI systems on enterprise tiers"), and require client acknowledgment. This is not a disclaimer - it is the foundation for everything else.

2. IP ownership allocation with an AI carve-out. Standard work-for-hire language treats all outputs as the client's. But purely AI-generated material may not be copyrightable, which makes a blanket assignment clause vulnerable. Use language that assigns human-authored elements fully and addresses AI-generated components separately - either as a licence, a best-efforts ownership grant subject to law, or an explicit mutual acknowledgment that copyright protection is contingent on human contribution.

3. Indemnity pass-through (or explicit exclusion). If you are on an enterprise plan that includes vendor IP indemnity, your MSA should specify whether that protection is passed to the client and under what conditions. If it is not passed through - or if you are on a plan without indemnity - your MSA should say so explicitly, so the client cannot later claim they assumed they were covered.

4. Regulatory compliance responsibility. If you are producing AI content for EU distribution, the contract should clarify which party holds deployer obligations under Article 50, who is responsible for ensuring machine-readable marking survives delivery, and who maintains the documentation record if a regulator or platform asks. Leaving this vague means both parties assume the other handled it.

5. Audit and records access. Enterprise clients are already beginning to add audit rights clauses for AI-assisted work. Getting ahead of this by including a standard clause - agreeing to maintain production records and making them available on reasonable request - is easier than negotiating ad hoc under time pressure later.

Why documentation is the real answer

Copyright law's current position, vendor indemnity terms, and EU AI Act deployer obligations all converge on the same underlying point: liability exposure shrinks dramatically when you can show a clear, contemporaneous record of what happened.

As the Copyright Office's 2025 report makes clear, your claim to copyright protection depends on whether you can show what a human actually contributed, and when. "AI governance is also evidence governance" is the report's practical conclusion. For the EU AI Act's editorial exemption, the Code of Practice's first draft requires that deployers relying on it keep internal documentation of their labelling practices and retain specific logs of their review process.

For vendor indemnity to apply, you need to be able to show you were on the right plan, used the model within its permitted parameters, and did not make modifications that triggered a carve-out.

In all three cases, the evidence looks similar: which model, on which plan, which version was shown to the client, what edits were made by a human, who reviewed and approved the final asset, and when each of those things happened.

That is exactly what Archibal is built to capture. Every project in Archibal records the AI generation points, the models used, the plan tier, the sign-off chain with timestamps, and the content hashes of delivered assets. When questions arise - from a client, a platform, or a regulator - those records are not reconstructed from memory or assembled from Slack screenshots. They are already there.

The broader point holds even for teams not using Archibal: the liability question for AI creative work is not primarily a legal theory question. It is a records question. What can you show, and how quickly can you show it? The agencies that have a clean answer to that question will be the ones that navigate this period with the least friction.

The practical checklist

Before shipping AI-assisted work with commercial stakes or EU distribution:

  • Confirm you are on an enterprise or API plan that includes vendor IP indemnity for the tools you used. If not, document the gap and address it in your contract.
  • Record human creative contributions. Keep source files, draft iterations, and revision history that shows what your team actually changed. Prompts are useful context but are not evidence of authorship.
  • Use project-level tracking. Know which assets in a campaign were AI-generated, which were AI-manipulated, and which were human-created. That distinction matters for copyright registration, client deliverables, and EU Article 50 compliance.
  • Write the editorial review into the workflow, not out of it. If you are relying on the Article 50 editorial exemption for text, make the review real and record it - named reviewer, timestamp, version reviewed.
  • Update your MSA. If your standard client agreement was drafted before 2024, it almost certainly does not address AI content adequately. At minimum it needs AI disclosure, IP allocation language, and clarity on who holds Article 50 deployer obligations for EU-facing work.
  • Get sign-off into a system, not email. A formal timestamped record of who approved which version for which market is worth more than any internal policy document.

Put simply: the agencies that treat AI records the same way they treat client briefs and approvals - as real assets that need to be stored, structured, and findable - will be substantially better positioned than those that treat AI as an undocumented production shortcut. The law is still moving, but the direction is clear.

If your agency ships AI-assisted work, see how Archibal builds that record for creators and agencies.

© 2026 Archibal.AI Inc. All rights reserved.