Cover image for “You can't copyright most of what your AI makes, and that's your smaller problem”
← essays · 2026-06-30

You can't copyright most of what your AI makes, and that's your smaller problem

Where AI and copyright actually stand for marketers as of mid-2026: why prompt-only output gets no protection after the Copyright Office's 2025 reports and the Thaler ruling, what the training-data cases (Bartz, Kadrey, Thomson Reuters, NYT) mean for the content you publish, and the fine print in your vendor's indemnification that decides who pays when an output infringes.

Current as of June 30, 2026. Written for marketers who make content with AI, not legal advice — confirm specifics with counsel.

Two copyright questions hang over every AI-assisted marketing workflow, and most teams only worry about the wrong one. The first: can you own what the model makes? The second, which matters more: can you be sued for it? The 2025 rulings answered the first more clearly than people expected and left the second deliberately unsettled.

You probably don’t own the output

In January 2025 the US Copyright Office published Part 2 of its AI report, and the core holding is blunt: prompts alone don’t earn copyright. Not detailed prompts, not iterative ones. The Office’s reasoning is that refining a prompt is “re-rolling the dice” on the model’s interpretation, not authoring the expression that comes out. Copyright protects human authorship, and a prompt directs a machine rather than fixing a person’s creative choices in the work.

That doesn’t leave you with nothing. The Office laid out where protection survives: a human-created work that remains perceptible in the output (your own illustration fed into an image model, your photography used as a reference) keeps its copyright, and your selection, coordination, and arrangement of AI-generated pieces can qualify if it clears the low originality bar from Feist. The protection is real but thin. It covers your contribution, not the AI-generated expression itself.

The courts backed this up. In Thaler v. Perlmutter, the DC Circuit affirmed in March 2025 that a machine can’t be an author, and the Supreme Court denied review in March 2026. That settles the extreme case: a work with no human creative input gets no copyright. What it doesn’t settle is the question every marketer actually has — how much human involvement is enough. Thaler disclaimed all human authorship, so the court never had to draw the line. A pending case, Allen v. Perlmutter, puts a Midjourney image made with 600-plus iterative prompts in front of a court to test exactly that. Until it resolves, the operative standard is the Office’s qualitative one: did a human determine enough of the expressive choices? The more you edit, select, arrange, and seed with your own material, the stronger your claim, and the Office has registered hundreds of AI-assisted works on that basis since 2023, each covering only the human layer.

The practical version: copy a model drafts from a one-line brief is unprotectable, and a competitor can lawfully lift it. Copy your team substantially rewrites, arranges, and shapes carries a thin copyright in the human contribution. If you want to own it, you have to work it.

The bigger exposure is on the way in, not the way out

Owning your output is a nuisance problem. Getting sued over the model’s training data is the one with nine-figure numbers attached, and 2025 was the year the courts started answering it. They split three ways.

In Bartz v. Anthropic, Judge Alsup held in June 2025 that training a model on lawfully acquired books is “exceedingly transformative” and qualifies as fair use. Then he split the question: maintaining a central library of pirated books was its own act, and not fair use. Anthropic settled the piracy exposure for $1.5 billion across roughly 482,000 works, about $3,000 a book, the largest copyright settlement in US history. The rule that fell out of it is clean: how you acquired the data can matter as much as what you did with it.

Two days later, in Kadrey v. Meta, Judge Chhabria also found fair use, but on narrower ground. The authors lost because they produced no evidence of market harm, and Chhabria went out of his way to say the ruling doesn’t bless AI training in general. He floated a theory future plaintiffs will use: “market dilution,” the idea that a flood of AI-generated work could substitute for the originals in the aggregate. Nobody proved it there. Someone will try.

The counterweight is Thomson Reuters v. ROSS. ROSS trained a legal-research tool on Westlaw headnotes to build a competing product, and the court rejected fair use outright. Same activity, opposite result, because the use was commercial and aimed at the same market. Put the three together and the fault line is visible: training looks like fair use when it’s transformative and doesn’t compete; it fails when the output substitutes for the source or the data was stolen.

That fault line is exactly what NYT v. OpenAI will test. The Times has exhibits showing near-verbatim reproduction of its articles under specific prompts, which takes aim at the “transformative” defense and at market harm at once. Summary judgment is expected in the second half of 2026. In music, the labels have mostly moved to licensing: Universal settled with Udio in October 2025 on a per-generation royalty of roughly $0.002 to $0.005, and the template that deal sets may matter more than any single ruling.

None of this is settled law. It’s a moving set of district-court decisions, a billion-dollar settlement, and one appellate case on authorship. But the direction is clear enough to act on.

Read your vendor’s indemnification, not its marketing

Every major enterprise AI vendor offers copyright indemnification now, and the protection is narrower than the announcement implied. The recurring exclusions, as of mid-2026:

  • Free and personal tiers get nothing. OpenAI’s Copyright Shield, Microsoft’s Copilot commitment, Google’s and Anthropic’s programs all cover paid enterprise and API use only. ChatGPT Plus and the free tiers are out.
  • Disabling the safety filters voids coverage across every vendor. The indemnity is conditioned on leaving the guardrails on.
  • “Knew or should have known” voids it too. A vague standard that quietly shifts risk back to you.
  • Trademark and publicity rights are excluded by most. The indemnity is copyright only, so an AI image that reproduces a logo or a recognizable face is your problem.
  • Your uploaded reference images shift liability to you. Feed a competitor’s asset or licensed stock in as a reference and you’ve stepped outside the coverage.

The reassuring fact underneath the litigation is that Bartz and Kadrey both turned partly on findings that current models don’t usually reproduce training works verbatim. The NYT exhibits are the exception that could undo that, which is why “write this in the style of [specific publication]” and prompts aimed at reproducing known content are the ones to keep out of your workflows.

The rest of the world isn’t aligned

In the UK, the High Court ruled in Getty v. Stability AI in November 2025 that a model’s weights are not “infringing copies” of the training images, because the model stores statistical parameters, not the pictures. Getty kept a partial trademark win where outputs reproduced its watermark. The UK government then declined to introduce a broad text-and-data-mining exception in March 2026, after 88% of consultation respondents opposed it. The EU runs the opposite system: the AI Act makes model providers publish training-data summaries and honor the opt-out that rights holders can set under the DSM Directive, which turns Europe into a license-or-opt-out regime. If you operate across these markets, the same content carries different risk in each.

What to actually do

  • Claim copyright by earning it. Edit, select, arrange, and seed with your own assets. Document the human work. Prompt-only output is a gift to your competitors.
  • Disclose AI in registrations. The Office requires you to disclaim AI-generated elements and describe the human contribution. Filing without disclosure when AI did the heavy lifting is grounds for cancellation.
  • Read the indemnity exclusions before you rely on the headline. Confirm your tier is covered, keep the safety filters on, and treat trademark and publicity as uncovered.
  • Keep verbatim-reproduction prompts out of the building. Don’t instruct models to imitate a named source or recreate known content.
  • Treat training-data provenance as a procurement question. Ask vendors where their data came from and what they’ll indemnify, and write the answers into the contract.

You don’t need to predict how NYT v. OpenAI comes out. You need a workflow where humans do enough of the creative work to own it, the safety features stay on, and your contracts say who pays if an output infringes. That’s available today, and it’s cheaper than the alternative by about $3,000 a book.