RatedWithAI

RatedWithAI

Accessibility scanner

AI CopyrightSeptember 21, 2026

Nobody Cleared the Output. The Prompt Log Is the Only Evidence You Have.

The training-data fight belongs to the model vendors. A claim against a business is about the asset it published — and it is decided on a side-by-side comparison that takes about four seconds to make.

The record is made at generation time or not at all. Independent creation is a real answer to a similarity claim, and it is an evidentiary one. The brief, the prompt history and the check take three minutes at the moment of creation and cannot be reconstructed two years later, which is when the letter arrives.

Why the Argument You Have Been Reading About Is Not Yours

Businesses have been following the training-set cases as though the outcome decided their exposure. It mostly does not.

The training question is not your question

Whether a model was lawfully trained is litigated between rightsholders and model developers, and it will be answered on a timeline no marketing calendar can wait for. A claim aimed at a business that published an asset is narrower and older than that: this output resembles my work, you had access to my work through the tool, and you distributed it. None of the training-set arguments reach that claim.

Access is now cheap to assume

The traditional hard half of an infringement claim is proving the defendant saw the original. A model trained on a large web corpus makes that assumption easy to plead, and a prompt that names a living artist, a franchise or a campaign supplies it directly. The practical effect is that the fight moves almost entirely onto similarity.

Independent creation is a defense you have to be able to show

It is a real answer to a similarity claim, and it is an evidentiary one. A team that can produce the brief, the prompt history, the intermediate versions and the timestamps is making that argument with records. A team that has the final JPEG and nothing else is making it as an assertion.

The asset that carries the risk is usually not the one you worried about

Hero images get reviewed. The exposure sits in volume: thumbnails, ad variants, social cutdowns, deck illustrations, product mockups, and the icon set someone generated in an afternoon. Those are produced by people with no review step, published to channels with no gate, and are the ones a rightsholder's own monitoring tooling surfaces.

Six Steps, Three Minutes, Done at Generation Time

1. Record the brief before the prompt

One or two lines stating what the asset is for and what it must show. This is the document that establishes the work started from a business need rather than from someone else's picture, and it costs nothing to write at the time and cannot be written afterwards.

2. Keep the full prompt history, including the discarded attempts

Every prompt, every revision, model and version, date and operator. Teams resist keeping the discarded attempts because they look bad. They are the record that shows the direction of travel — and their absence is far worse, because an incomplete log invites the inference that the missing part is the damaging part.

3. Screen the prompt for names

A named artist, studio, franchise, character, brand or campaign in a prompt is the single most quotable line in the whole file. Replace names with descriptions of the attributes you actually want — palette, era, composition, medium. This is a style-guide change enforced at the prompt box, not a legal review that happens later.

4. Run a similarity check on the output, not the prompt

Reverse image search on the final asset, plus a search for the obvious source if the aesthetic is recognisable. For text, a passage-level check against the web. This takes minutes and catches the category that matters: outputs that reproduce a specific protected expression rather than a general style.

5. Check the marks and the faces separately

Copyright is one regime among several sharing the same asset. Logos, trade dress and product shapes raise trademark questions; a recognisable person raises publicity and, in some states, a specific synthetic-likeness statute. A clean copyright screen says nothing about either, and the same image can clear one and fail the other.

6. Attach the record to the asset, not to a person

Store the brief, prompts, checks and approver alongside the file in the asset manager, with the same retention as the campaign. Clearance records that live in the generating designer's chat history leave the company when they do, and that is exactly when a claim about a two-year-old campaign arrives.

Four Tiers, and Only One of Them Belongs in Production

Style without specificity

Looks like: 'Flat vector illustration, muted palette, isometric perspective' — an aesthetic many people work in.

How it reads: Lowest exposure. Style as such is not what copyright protects; protection attaches to particular expression. This is where you want most of your generated volume to sit, and a prompt standard that describes attributes rather than sources is what keeps it there.

Named living creator or studio

Looks like: 'In the style of [artist]' or a prompt naming an animation studio's house look.

How it reads: High exposure, and self-documenting in the worst way. The prompt supplies access, signals intent, and reads badly to a non-specialist. Even where the output is defensible, this is the line that gets quoted. Ban it in the prompt standard.

Recognisable character, property or campaign

Looks like: A figure that reads as a specific character, or a layout that reproduces a known campaign.

How it reads: The highest exposure and also the most likely to be found automatically, because these rightsholders run monitoring. Copyright and trademark both engage, and the commercial use makes the fair-use argument materially harder than it would be for commentary.

Near-reproduction of a specific work

Looks like: An output that a side-by-side comparison makes obviously derived from one identifiable image or passage.

How it reads: This is the infringement case regardless of how it was produced. No indemnity, disclaimer or attribution changes it. The clearance step exists to catch this before publication, because after publication the only remaining decisions are takedown and settlement.

The Indemnity You Are Relying On Has Conditions

It covers the tier you pay for

Output indemnities are typically a paid-plan feature. Assets generated on free seats, personal accounts or a contractor's own subscription are outside the policy that the legal team believed applied. Audit which accounts actually produced the published library before relying on the clause.

It is conditioned on not disabling the filters

Vendors condition coverage on using the safety systems as shipped. Teams that route around a filter to get the shot they wanted — a different endpoint, an older model, a jailbreak prompt — have usually voided the clause in the same act that created the risk.

It excludes outputs you prompted toward a known work

Deliberately steering at a specific protected work is a standard carve-out, and the prompt log proves whether you did. This is the clause that makes step 3 above a commercial control rather than a stylistic one.

It covers defense costs, not your business interruption

Even a fully honoured indemnity does not un-publish the campaign, restore the ad account or repair the client relationship. Pulling a live campaign is the cost that lands first and is never covered, which is why the pre-publication check is worth more than the clause.

It runs to the account holder, not to your client

Agencies sit in the middle of this. The vendor indemnifies the account holder; the client agreement usually has the agency warranting non-infringement of everything delivered. Those two documents do not meet, and the gap is the agency's balance sheet.

Questions Marketing and Legal Ask Each Other

Is style copyrightable? Our prompts only describe an aesthetic.

Style in the abstract is not what copyright protects — protection attaches to particular expression, not to a technique, palette or genre. That is a genuine and useful distinction, and it is why prompts written as attribute descriptions sit in a materially safer place than prompts written as references to a person. The caution is that the line between a style and a specific work is drawn on the output, not on the prompt. A model asked for a general aesthetic can still return something that reproduces recognisable elements of one image it learned the aesthetic from, particularly for distinctive or thinly populated styles. So the style argument protects the intent and the similarity check protects the asset, and a workflow needs both. A second caution: even where copyright does not reach a style, other regimes can reach the same output — trade dress, publicity rights, and synthetic-likeness statutes all operate independently.

Do we have to disclose that an asset was AI-generated?

It depends on the surface rather than on a single rule, so the answer is usually a list rather than a yes or no. Platform policies increasingly require synthetic-media labelling for advertising and for political or social-issue content, and those are contractual obligations enforced by account action. Advertising law reaches any depiction that misleads about the product, a person's endorsement, or a result a customer can expect — an AI-generated 'photo' of a product configuration you do not sell is a substantiation problem before it is a disclosure problem. Some jurisdictions have specific provenance and labelling regimes, and client contracts frequently now carry their own disclosure clause. The workable approach is a matrix by channel maintained by whoever owns the channel, plus provenance metadata attached at generation so the disclosure decision can be made later without archaeology.

Can we register copyright in an AI-assisted asset?

Registration is available for the human-authored contribution, and the application has to disclose the AI-generated material and disclaim it. Purely machine-generated output has no human author to hold a copyright, which means the parts of your campaign that nobody meaningfully arranged, selected or modified may be unprotectable — anyone can copy them. That is the mirror-image risk to infringement and it lands on brand assets specifically: a logo or mascot generated end to end and never meaningfully reworked is a poor thing to build a brand on, whereas a trademark claim over it can still exist through use in commerce. The practical implication for an in-house team is to keep human selection and modification visible in the file history for anything you intend to own, and to be honest on the application, because a registration obtained without disclosure is vulnerable at exactly the moment you want to rely on it.

A contractor delivered assets. Are we covered by their warranty?

You have a contractual claim against them, which is not the same as being covered. A freelancer's non-infringement warranty is worth what the freelancer is worth, and a rightsholder will name the party that published and profited — which is you. Three changes make the position defensible. First, require disclosure of AI use per deliverable rather than a blanket clause, because you cannot run a clearance workflow on assets you do not know are generated. Second, require the clearance record itself to be delivered with the asset: brief, prompts, checks. Third, deal with ownership explicitly — if a deliverable has no human author there may be nothing to assign, so the agreement should also assign whatever rights exist in the human-authored elements and warrant that the contractor holds them. Most standard contractor templates predate all three points and say only that the contractor owns what they deliver.

How long should we keep prompt logs?

At least as long as the statute of limitations for an infringement claim in the jurisdictions you publish in, and as a rule of thumb keep them for the life of the asset plus a comfortable margin, because the claim arrives about the campaign you have forgotten. The tension is with privacy-driven data minimisation schedules, which routinely destroy tool logs on a short cycle and take your independent-creation evidence with them. Resolve it deliberately: classify clearance records as evidentiary rather than operational, store them with the asset instead of inside the generation tool, and exclude them from the tool's default retention. A prompt log stored only in a vendor's chat history is also a log you lose when a seat is deprovisioned or the vendor is switched, which happens far more often than a lawsuit does.

The Oldest-Asset Test

Open the oldest AI-generated image still running in a live campaign. Try to answer four questions from records that exist today: which model made it, who prompted it, what the prompt said, and whether anyone checked the result against anything.

If the answer to any of them is a person's memory, that asset has no independent creation evidence behind it. The clearance workflow is not there to slow down the next asset. It is there so the next question about an old one has an answer.

Related Reading