Rights, licenses and provenance of AI-generated content
A generated image may have no owner, a song may carry a lawsuit and, since August 2, 2026, an unlabeled deepfake can draw a fine in Europe. Here is what brand teams need to know and do, with dates and sources.
In the US, a prompt alone does not make AI output copyrightable: the Copyright Office (January 29, 2025) requires human authorship. Training data is being priced in court: Anthropic's book-piracy settlement was approved on July 20, 2026, a Munich court ruled against Suno and the music majors are split between licenses and new lawsuits.
Since August 2, 2026, the EU AI Act requires marking of synthetic content and disclosure of deepfakes (Article 50). C2PA and SynthID help, but they prove origin, not truth, and can be stripped. Brand teams need approved tools, logs, documented human authorship, labels, likeness consent and contract clauses.
Who owns AI output
The clearest official position is American. The Copyright Office's Part 2 report (January 29, 2025) says prompts alone do not make output copyrightable; protection requires human authorship through expressive input, selection and arrangement, or modification.
In the US, a purely generated image or jingle may therefore have no copyright owner, and you may be unable to stop others from reusing it. A vendor's terms give you a contractual license, not protection against third parties. Our rule in every market: count on exclusive rights only for what a person demonstrably made or shaped, and check the local position with counsel before registering or licensing a work.
| Tool and plan | Commercial use | Limits |
|---|---|---|
| Suno Free | No, personal use only | 7 lifetime trial downloads |
| Suno Pro / Premier | Yes | 20 or 60 downloads per month |
| ElevenLabs Music | Starter: yes, no streaming; Creator and Pro: yes, not enterprise; Enterprise: all uses | Free: personal only; self-serve plans exclude film, TV and studio games |
| Stable Audio 3.0 (open weights) | Yes, under the Community License | Enterprise license above $1 million in annual revenue |
Lawsuits and settlements: where they stand
Checked on September 26, 2026; not an exhaustive list.
| Case | Court and date | Status |
|---|---|---|
| Bartz v. Anthropic (books) | US class action | Settlement approved July 20, 2026; first payments expected by Nov 15, 2026 |
| UMG, Sony, Warner v. Suno | Federal court, Boston, June 24, 2024 | Warner settled (Nov 2025); UMG and Sony seek up to $150,000 per work on 560 recordings |
| Sony, UMG v. Suno (v6) | Boston, Sept 18, 2026 | New suit alleging v6 launders infringement; 60,202 recordings cited |
| UMG, Sony, Warner v. Udio | Federal court, New York, June 24, 2024 | UMG and Warner settled (Oct and Nov 2025); Sony filed a second suit over about 30,000 songs (July 2026) |
| GEMA v. Suno | Munich Regional Court, announced July 31, 2026 | Infringement through training, storing and reproducing works; outputs matched originals |
| Koda and SOCAN v. Suno | Denmark (Nov 2025), Canada (Sept 2, 2026) | Pending |
The evidence is getting specific: in a September 8, 2026 filing, Suno admitted it obtained training audio from YouTube with the yt-dlp tool, and the judge had already let the labels add a DMCA anti-circumvention claim. Meanwhile, litigation is turning into licensing: UMG and Warner have licensed Udio; Warner, BMG and Believe have deals with Suno; and UMG signed with ElevenLabs on September 10, 2026.
Licensed does not mean frictionless. Udio disabled downloads after its UMG deal, Believe blocked tracks from Suno's older models in April 2026 before signing, and Deezer tags AI music and keeps it out of recommendations. Check distribution rules, not just the generator's terms.
Vendor indemnities: useful, but conditional
Some vendors promise to defend business customers against IP claims over outputs, under conditions. Microsoft's Customer Copyright Commitment requires Azure OpenAI customers to use a metaprompt against infringement, test and document their application, and switch on the protected-material and jailbreak filters for text and code; to tender a claim you must prove compliance. Google (October 2023) covers training data and generated output, but not intentional infringement. Anthropic (December 2023) defends commercial API customers against copyright claims over authorized use.
- Scope: the promise covers the customer who signed, on the services listed. A freelancer's personal account is outside it.
- Claims: Anthropic names copyright; Google and Microsoft name intellectual property. Likeness, voice, defamation and data protection need their own analysis.
- Conditions: filters on, testing done, no intentional infringement. Keep the evidence: you will have to show it.
- Inputs: treat the reference images, voices and brand assets you upload as your own responsibility.
Likeness and voice: consent first
In the EU, deepfakes must be disclosed (Article 50(4)) and, from December 2, 2026, systems that generate intimate images of identifiable people without their explicit consent are banned (Article 5(1)(ba)). In Colombia, Law 2502 of 2025 raises the penalty for impersonation using AI, and biometric data are sensitive data under Law 1581, so they need explicit authorization. In France, Law 2023-451 requires the words “Images virtuelles” on commercial influencer content showing AI-generated faces or bodies. In Texas, TRAIGA bans AI developed or deployed to produce unlawful sexual deepfakes.
Industry is moving too. Warner's deal with Suno lets artists opt in to the use of their names, likenesses and voices; Google's Lyria blocks prompts for specific artists' voices; YouTube lets verified adults find AI versions of their face and request removal; Spotify has an impersonation policy and badges AI-generated artist personas. Musician Jason Isbell has filed a proposed class action against Suno over the use of artists' identities.
Article 50 and the EU code on marking and labeling
Article 50 has applied since August 2, 2026; the Omnibus only gave generators already on the market until December 2, 2026 to mark outputs. The code of practice on AI-generated content, final since June 10, 2026, is recognised by the Commission and the AI Board as an adequate voluntary tool. About 190 organisations had signed by the end of July, including Anthropic, Google, Meta, Microsoft and OpenAI as providers and brands such as Bulgari, Lufthansa and Lenovo as deployers.
| Who | Duty | How |
|---|---|---|
| Provider of a generator | Machine-readable marking (50(2)) | At least two layers, signed metadata and an imperceptible watermark; interoperable detection by Feb 2, 2027 |
| Provider of a chatbot | Say it is an AI (50(1)) | Clear notice at the first interaction, unless obvious |
| Brand publishing a deepfake | Disclose it (50(4)) | Label or icon visible at first exposure; for video, at the start and at intervals |
| Publisher of AI text on public-interest matters | Disclose it (50(4)) | Unless a human reviewed it under editorial responsibility |
Evidently artistic or satirical works get a lighter regime, but the label must remain perceivable. On September 24, 2026 the EU published optional icons (basic, fully AI-generated, partially AI-modified) and stressed that the labeling duty itself is mandatory. Breaches can cost up to €15 million or 3% of worldwide turnover; the wider framework is in our 2026 regulatory map.
C2PA and SynthID: what they prove and what they don't
| Aspect | C2PA Content Credentials | Google SynthID |
|---|---|---|
| What it is | A signed manifest bound to the file by a hash, optionally backed by a watermark | An imperceptible watermark in images, video, audio and text |
| What it proves | Who signed, what they declared (for example, AI generation) and that the file hasn't changed since | That content was created or edited with Google AI |
| What it doesn't | That the content is true; the manifest is lost if a platform strips metadata | Anything about non-Google content; text marks weaken after paraphrase or translation |
| Adoption | 219 conformant products from 128 organisations; 10 at Assurance Level 2 | Over 20 billion items marked by November 2025, per Google |
| Weak points | Forged camera signatures on rooted Pixel phones (Aug 2026); optional revocation checks | Paraphrase removed text marks in 98.3% of runs (July 2026 preprint); attacks on image marks |
Certifications jumped ahead of the EU deadline (60 in July 2026, against 11 in January), including generators from OpenAI, Amazon Bedrock, Stability AI and Runway and brand pipelines such as Mondelez's AIDA and BESTSELLER's StorM. Yet no Apple, Samsung, Canon, Sony, Nikon, Meta, Microsoft or TikTok product is on the conformance list, and Apple launched its own Reference Image system on September 15, 2026. NIST's conclusion stands: no single provenance or detection technique is a complete solution.
A practical policy for marketing and brand teams
Our recommended minimum, to adapt with your legal team.
| Area | Rule | Evidence |
|---|---|---|
| Approved tools | Listed tools only, on commercial plans, license and indemnity checked; prefer tools that attach Content Credentials | Tool register with plan and terms date |
| Logs | Prompt, model and version, date, inputs, outputs and edits for every published asset | Asset log and C2PA manifests |
| Human authorship | A person selects, arranges and edits; logos, legal lines and prices are added in post | Drafts, layered files, edit history |
| Labels | EU icon at first exposure for deepfakes; platform AI disclosures; “Images virtuelles” for French influencer content | Screenshots of published labels |
| Likeness and voice | No real person or recognizable voice without written, specific consent; no sound-alikes | Signed releases with scope and duration |
| Trademarks and music | Clear third-party marks, characters and music before publishing | Clearance checklist |
| Agencies and freelancers | Disclose AI use; approved tools only; deliver logs; assign rights; no client or personal data in consumer tools; apply Article 50 | Contract clauses |
If a real person, place or event looks real in the output, it needs consent, review and a label. Everything else still needs a log. For tool choices, see our reviews of image models and video models.
What it means for brands in Colombia, LatAm and Europe
Europe. Article 50 applies now, the code sets the method, and the Munich ruling shows European courts examine both training and outputs. Upstream, GPAI providers must respect text-and-data-mining opt-outs and publish training-content summaries (Article 53(1)), which gives rights holders more visibility.
Colombia and Latin America. Colombia has no AI law yet, but content aimed at EU audiences falls under Article 50 wherever it is made (Article 2(1)(c)), and Meta and YouTube require disclosure of realistic synthetic content. Law 1581 governs the use of identifiable people's faces and voices, the SIC warns that data found online is not public data, and Law 2502 of 2025 punishes AI impersonation. Disclosure also seems to cost few sales: in an IAB study, 73% of young US consumers said it would raise or not change their purchase intent.
Label realistic synthetic content by default in every market. It costs little, the EU requires it, and it keeps one workflow from Bogotá to Paris.
Key takeaways
- In the US, human contributions are protected, not prompts (Copyright Office, January 29, 2025): document selection, arrangement and edits.
- Music is the most active front: licenses with Warner and UMG coexist with new suits against Suno and a German ruling against it.
- Vendor indemnities are conditional and name copyright or IP; likeness and voice claims stay with you.
- Since August 2, 2026, EU law requires machine-readable marking and deepfake disclosure; the June 2026 code asks for two marking layers.
- C2PA and SynthID prove origin, not truth, and can be stripped: combine them with logs, labels and consent.
Sources
- Copyright and Artificial Intelligence (Part 2: Copyrightability)
- AI Act, Article 50: Transparency obligations
- Code of Practice on transparency of AI-generated content
- C2PA Conforming Products List
- SynthID
- Reducing Risks Posed by Synthetic Content (NIST AI 100-4)
- GEMA prevails over Suno
- Sony Music and Universal Music sue Suno over its label-backed model
- Suno admits it obtained YouTube audio to train its AI but challenges UMG and Sony's standing
- Bartz v. Anthropic: settlement website
- Customer Copyright Commitment: required mitigations
- Protecting customers with generative AI indemnification
Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.
The questions we hear often
Can I copyright an image I generated with AI?
In the US, not on the strength of prompts alone: the Copyright Office requires human authorship through expressive input, selection and arrangement, or modification (January 29, 2025). Document what a person contributed, and check the local position with counsel in other markets.
Does a vendor indemnity cover my campaign?
Only within its terms: the services listed, the claims it names (copyright or IP) and its conditions, such as Microsoft's required filters and testing or Google's exclusion of intentional infringement. Likeness and voice need separate clearance.
Do I have to label AI content in the EU?
Yes for deepfakes, and for AI-generated text on matters of public interest that no human reviewed under editorial responsibility (Article 50(4)), since August 2, 2026. Providers must also mark outputs in a machine-readable way. The EU icons of September 24, 2026 are optional; the duty is not.
Are C2PA or SynthID enough to comply?
They are examples of the two layers the EU code asks providers to combine (signed metadata and an imperceptible watermark). They don't replace the visible label a brand owes as deployer, and research shows both can be stripped or attacked.
Can we use AI music in ads?
Use tools and plans whose terms allow commercial use (for example Suno Pro or Premier, or ElevenLabs paid plans within their limits), avoid prompts that imitate specific artists, keep logs, and check distribution rules: some platforms tag AI tracks or exclude them from recommendations.
More analysis to read next
The 2026 AI regulatory map
The AI Act after the Omnibus, GDPR, Colombia's Law 1581 and SIC rules, LatAm, the US and ISO 42001: dates, duties and a 10-step plan for companies.
Image, video and audioImage models in 2026: which to use for brand work
Nano Banana 2 and Pro, GPT Image 2.5, Qwen-Image: which model to use for brand assets, what each image costs and what the AI Act requires since August 2026.
Image, video and audioVideo models in 2026: from demo to ad
Gemini Omni Flash, Veo 3.1, Kling 3.0, Seedance, Wan 3.0: what works for ads, what a second costs, what the Sora shutdown teaches and how to label in the EU.
Let's put it in production
Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.
I reply personally. No endless forms, no canned replies.