AI copyright for marketers: ownership is the smaller risk
Prompt-only AI output gets no US copyright, and the training-data cases set your liability. What marketers should know as of mid-2026, indemnities included.
Two copyright questions hang over every AI-assisted marketing workflow. Most teams worry about whether they can own what the model makes, when the question that costs money is whether they can be sued for it. The 2025 rulings answered the first more clearly than people expected and left the second open.
You probably don't own the output
In January 2025 the US Copyright Office published Part 2 of its AI report, and the core holding is blunt: prompts alone don't earn copyright, however detailed or iterative they are. In the Office's reasoning, refining a prompt is "re-rolling the dice" on the model's interpretation, and the person doing it still hasn't authored the expression that comes out. Copyright protects human authorship, and a prompt directs a machine without fixing any person's creative choices in the work.
That doesn't leave you with nothing. The Office laid out where protection survives: a human-created work that remains perceptible in the output (your own illustration fed into an image model, your photography used as a reference) keeps its copyright, and your selection, coordination, and arrangement of AI-generated pieces can qualify if it clears the low originality bar from Feist. That protection is thin: it covers your contribution and stops short of the AI-generated expression itself.
The courts backed this up. In Thaler v. Perlmutter, the DC Circuit affirmed in March 2025 that a machine can't be an author, and the Supreme Court denied review in March 2026. That settles the extreme case: a work with no human creative input gets no copyright. What it doesn't settle is the question every marketer has: how much human involvement is enough? Thaler disclaimed all human authorship, so the court never had to draw the line. A pending case, Allen v. Perlmutter, puts a Midjourney image made with 600-plus iterative prompts in front of a court to test exactly that. Until it resolves, the operative standard is the Office's qualitative one: did a human determine enough of the expressive choices? The more you edit, select, arrange, and seed with your own material, the stronger your claim, and the Office has registered hundreds of AI-assisted works on that basis since 2023, each covering only the human layer.
The practical version: copy a model drafts from a one-line brief is unprotectable, and a competitor can lawfully lift it. Copy your team substantially rewrites, arranges, and shapes carries a thin copyright in the human contribution. If you want to own it, you have to work it.
The bigger exposure comes from training data
Owning your output is a nuisance problem. The model's training data is where the nine-figure numbers are, and in 2025 the courts started ruling on it, in three different directions.
In Bartz v. Anthropic, Judge Alsup held in June 2025 that training a model on lawfully acquired books is "exceedingly transformative" and qualifies as fair use. Then he split the question: maintaining a central library of pirated books was its own act, and not fair use. Anthropic settled the piracy exposure for $1.5 billion across roughly 482,000 works, about $3,000 a book, the largest copyright settlement in US history. The lesson is clean: how you acquired the data can matter as much as what you did with it.
Two days later, in Kadrey v. Meta, Judge Chhabria also found fair use, but on narrower ground. The authors lost because they produced no evidence of market harm, and Chhabria went out of his way to say the ruling doesn't bless AI training in general. He floated a theory future plaintiffs will use: "market dilution," the idea that a flood of AI-generated work could substitute for the originals in the aggregate. Nobody proved it in Kadrey, and someone will try.
The counterweight is Thomson Reuters v. ROSS. ROSS trained a legal-research tool on Westlaw headnotes to build a competing product, and the court rejected fair use outright. The activity was the same and the result was the opposite, because the use was commercial and aimed at the same market. Put the three together and the fault line is visible: training looks like fair use when it's transformative and doesn't compete; it fails when the output substitutes for the source or the data was stolen.
That fault line is what NYT v. OpenAI will test. The Times has exhibits showing near-verbatim reproduction of its articles under specific prompts, which takes aim at the "transformative" defense and at market harm at once. Summary judgment is expected in the second half of 2026. In music, the labels have mostly moved to licensing: Universal settled with Udio in October 2025 on a per-generation royalty of roughly $0.002 to $0.005, and the template that deal sets may matter more than any single ruling.
None of this is settled law. What exists is a handful of district-court decisions, a billion-dollar settlement, and one appellate case on authorship, and the direction is still clear enough to act on.
What vendor indemnification excludes
Every major enterprise AI vendor offers copyright indemnification now, and the protection is narrower than the announcement implied. The recurring exclusions, as of mid-2026:
- Free and personal tiers get nothing. OpenAI's Copyright Shield, Microsoft's Copilot commitment, and Google's and Anthropic's programs all cover paid enterprise and API use only, so ChatGPT Plus and the free tiers are out.
- Disabling the safety filters voids coverage across every vendor, because the indemnity is conditioned on leaving the guardrails on.
- A "knew or should have known" clause voids it too, and that vague standard quietly shifts risk back to you.
- Most programs exclude trademark and publicity rights. The indemnity covers copyright only, so an AI image that reproduces a logo or a recognizable face is your problem.
- Uploaded reference images shift liability to you. Feed a competitor's asset or licensed stock in as a reference and you've stepped outside the coverage.
The reassuring fact underneath the litigation is that Bartz and Kadrey both turned partly on findings that current models don't usually reproduce training works verbatim. The NYT exhibits are the exception that could undo that, which is why "write this in the style of [specific publication]" and prompts aimed at reproducing known content are the ones to keep out of your workflows.
The UK and EU run different systems
In the UK, the High Court ruled in Getty v. Stability AI in November 2025 that a model's weights are not "infringing copies" of the training images, because the model stores statistical parameters, not the pictures. Getty kept a partial trademark win where outputs reproduced its watermark. The UK government then declined to introduce a broad text-and-data-mining exception in March 2026, after 88% of consultation respondents opposed it. The EU runs the opposite system: the AI Act makes model providers publish training-data summaries and honor the opt-out that rights holders can set under the DSM Directive, which turns Europe into a license-or-opt-out regime. If you operate across these markets, the same content carries different risk in each.
What to do
- Claim copyright by earning it: edit, select, arrange, and seed with your own assets. Document the human work. Prompt-only output is a gift to your competitors.
- Disclose AI in registrations: the Office requires you to disclaim AI-generated elements and describe the human contribution. Filing without disclosure when AI did the heavy lifting is grounds for cancellation.
- Read the indemnity exclusions before you rely on the headline. Confirm your tier is covered, keep the safety filters on, and treat trademark and publicity as uncovered.
- Keep verbatim-reproduction prompts out of the building: don't instruct models to imitate a named source or recreate known content.
- Treat training-data provenance as a procurement question: ask vendors where their data came from and what they'll indemnify, and write the answers into the contract.
You don't need to predict how NYT v. OpenAI comes out. You need a workflow where humans do enough of the creative work to own it, the safety features stay on, and your contracts say who pays if an output infringes. That's available today, and it's cheaper than the alternative by about $3,000 a book.