$1.5B
Anthropic's Sept 2025 copyright settlement in Bartz v. Anthropic
5
FTC 'Operation AI Comply' enforcement actions in a single sweep
Aug 2, 2026
Date EU AI Act Article 50 transparency rules bite
0
US copyright registrations granted to purely AI-generated works
Something changed in the last 18 months that most content creators still have not internalized: the legal risk of AI content generation is no longer theoretical, and it is no longer confined to big tech. It now shows up in freelance contracts, client compliance reviews, platform terms of service, and -- when things go badly -- your personal liability exposure.
Here is the trap. Most people assume the danger of AI content is getting caught. It is not. Nobody sues you because a detector flagged your blog post. They sue you because:
- Your AI-drafted product page made a factual claim you cannot substantiate.
- Your AI voice clone sounded like a working narrator with a recognizable voice.
- You registered a copyright in a work the Copyright Office later cancelled because a machine -- not a human -- supplied the expressive elements.
- Your fine-tuned model was built on scraped data.
- You published AI-generated text about matters of public interest in the EU without a disclosure.
That is five different bodies of law touching one workflow: copyrightability, infringement, transparency, consumer protection, and personality rights. Almost nobody maps how they intersect. This guide does.
The one-sentence version
In the US you may not own what you generate. In the EU you may have to label it. In the UK the rules are still being written. And in all three jurisdictions, you remain fully liable for what it says.
Before we go further: if part of your anxiety is whether your skill set survives the next three years, that is a different question than legal risk -- but not an unrelated one. Use our free Career Pulse Score to see how future-proof your current work actually is. It takes about four minutes and it will tell you whether you are building a moat or digging one.
What The Law Actually Says
1. Copyright: you cannot own what a machine wrote
US law is blunt on the headline point. 17 U.S.C. Section 102(a) protects "original works of authorship." The US Copyright Office has interpreted that phrase, consistently since 2023, to require human authorship. Not human prompting. Human authorship.
The line of authority you need to know:
- Zarya of the Dawn (February 2023). The Office partially cancelled Kristina Kashtanova's registration for a comic book whose images were produced with Midjourney, holding the images were not the product of human authorship. The human-written text and the human-arranged layout survived. The images did not.
- Thaler v. Perlmutter (2023, affirmed by the D.C. Circuit in March 2025). A work generated by an AI system with no human author cannot be registered at all. The appeals court rejected the argument that an AI system or its owner could be the statutory author.
- Copyright Office Part 2 Report (January 2025). Prompts alone "do not alone provide sufficient control" over the resulting output. Copyright can exist in human-authored expression that is perceptible in the final work -- selection, arrangement, substantial editing -- but the AI-generated material itself is unprotected. See the Copyright Office AI initiative page for the full report and registration guidance.
Plain language: if you paste a prompt, take the output, and publish it, you probably have no copyright in that text. Anyone can copy it. If someone else's model produces something nearly identical to yours, you likely have no infringement claim. The upside of the same rule: you also cannot infringe a copyright that does not exist, so purely AI-generated output from a lawfully trained model is not automatically an infringement -- it is a liability question about the training data, not the output.
2. Training data: the input side is where the money is
Almost every dollar of AI copyright litigation has been about inputs, not outputs. A short list of the cases that define the terrain:
- The New York Times v. OpenAI (S.D.N.Y., filed December 2023) -- alleges millions of Times articles were used in training.
- Authors Guild v. OpenAI (S.D.N.Y., 2023).
- Andersen v. Stability AI (N.D. Cal.) -- Judge Orrick allowed direct infringement claims to proceed in August 2024, rejecting the argument that the model itself was not a "copy."
- Getty Images v. Stability AI -- parallel proceedings in the US (D. Del.) and the UK. In November 2025, the UK High Court largely rejected Getty's copyright claims, finding that training and development of the model in the UK did not infringe UK copyright, while allowing a narrow trademark claim to continue to trial.
- Bartz v. Anthropic -- settled in September 2025 for $1.5 billion, roughly $3,000 per work across an estimated 500,000 works. The largest AI copyright settlement on record, and the number every general counsel now uses as a benchmark when negotiating indemnities.
If you are a solo creator, you are unlikely to be the defendant here. But you are very likely to be the customer -- and indemnification is now the front line of every enterprise AI contract. When a client asks you to warrant that your AI-assisted deliverable does not infringe any third-party rights, they are transferring the training-data risk of the model you used onto you.
3. Outputs: substantial similarity is not dead
If a generated output is substantially similar to a protected work, ordinary infringement analysis still applies. Courts have not accepted the argument that an autonomous system's output launders liability. "The AI did it" is not a defense -- it is a description of your toolchain, and you chose the toolchain.
4. Transparency: the wave you cannot ignore
Regulation (EU) 2024/1689 -- the EU AI Act -- is the first binding, cross-sector transparency regime for synthetic content. Article 50 requires:
- Providers of generative AI systems must mark outputs in a machine-readable format and ensure they are detectable as artificially generated or manipulated (Article 50(2)).
- Deployers who publish deepfakes must disclose that the content is artificially generated or manipulated (Article 50(4)).
- Deployers who publish AI-generated or manipulated text to inform the public on matters of public interest must disclose it -- unless the content underwent human review or editorial control and a person or entity holds editorial responsibility (Article 50(4), second paragraph).
Article 50 applies from 2 August 2026. Penalties under Article 99 reach EUR 15 million or 3% of global annual turnover, whichever is higher.
That human-review carve-out is the most operationally important sentence in the entire Act for content teams. It means editorial responsibility is a legal shield -- and a workflow requirement. If you cannot point to a named human who reviewed and took responsibility, you have no shield.
Practice tip
If you publish AI-assisted text on public-interest topics into the EU, keep documented evidence of human editorial review. Not a checkbox. A timestamped edit trail, a named editor, and a written editorial policy. That single artifact is the difference between a compliance posture and an enforcement action.
5. Consumer protection: the FTC does not care what wrote your copy
The FTC Act Section 5 (15 U.S.C. Section 45) prohibits unfair or deceptive acts or practices. In September 2024, the FTC launched Operation AI Comply -- five simultaneous enforcement actions.
The one that matters most for content people is Rytr. The FTC alleged the company provided a tool that generated fake reviews, and the resulting order restricts how the tool can be marketed and used. The signal is unmistakable: building or marketing a product whose core use case is deception is itself a violation, regardless of who pulls the trigger.
Endorsement disclosures, review authenticity, and substantiation of claims all fall under 16 CFR Part 255. AI does not change those rules. It just makes violations faster, cheaper, and vastly more numerous.
6. Defamation, right of publicity, and professional duty
A generated statement that a real, identifiable person did something false and defamatory is actionable. Walters v. OpenAI (Georgia, 2025) was dismissed on procedural grounds in May 2025, but the underlying theory -- that a model operator can be liable for defamatory hallucinated output -- survives and is being tested in other venues.
In Moffatt v. Air Canada (2024), a Canadian tribunal held an airline liable for what its customer-service chatbot told a traveler about bereavement fares. Your chatbot is you. Your autoresponder is you. Your AI-drafted FAQ page is you.
Right of publicity is tightening fast. Tennessee's ELVIS Act (effective July 1, 2024) explicitly covers AI-generated voice. The proposed federal NO FAKES Act would create a national digital-replica right. California's AB 853 requires disclosure when digital replicas of performers are used. If you are cloning voices or likenesses, you are in the highest-risk category in this entire field.
Professionals carry an extra layer. ABA Formal Opinion 512 (July 2024) confirms that lawyers using generative AI must understand its risks -- including hallucinated citations and confidentiality leaks -- before they use it. Medicine, accounting, and financial advice have comparable duties. If your professional advisor used AI badly on your matter, that is an ethics violation, not merely a mistake.
Jurisdiction Comparison: What Applies Where
The single biggest mistake content teams make is assuming one rule applies everywhere. It does not. Here is the current landscape across the three jurisdictions that cover most English-language work.
| Issue | United States | European Union | United Kingdom |
|---|---|---|---|
| Copyright in AI output | None absent human authorship (17 USC 102(a); Thaler; Copyright Office Part 2 Report, Jan 2025) | Human-authorship requirement applied by most member states; no harmonized AI-specific rule | CDPA 1988 s.9(3) contemplates "computer-generated" works; reform under active consultation |
| Training data | Case-by-case fair use (17 USC 107); multiple active suits including NYT v. OpenAI | TDM exceptions under Directive (EU) 2019/790 Arts. 3-4, subject to rightsholder opt-out | No broad TDM exception; government consultation closed Feb 2025, no legislation yet |
| Transparency / labeling | Sector rules plus state laws (CA AB 2013, CA AB 853, TN ELVIS Act); no federal mandate | AI Act Art. 50, applies 2 Aug 2026; fines to EUR 15M or 3% global turnover | ASA/CAP Code applies to advertising; no AI-specific statute yet |
| Consumer claims | FTC Act Sec. 5; Operation AI Comply; 16 CFR Part 255 endorsements | Unfair Commercial Practices Directive 2005/29/EC; DSA; AI Act | Consumer Protection from Unfair Trading Regulations 2008 |
| Deepfakes / likeness | Patchwork of state right-of-publicity laws plus ELVIS Act; NO FAKES Act proposed | AI Act Art. 50 disclosure duty for deepfakes | Defamation, data protection, and Online Safety Act 2023 |
| Data protection | State laws (CCPA/CPRA, BIPA); no federal omnibus regime | GDPR Arts. 5, 13-15, 22; AI Act data governance duties | UK GDPR plus ICO guidance on AI and automated decision-making |
What This Means For You
Legal exposure scales with what you sell and who you sell it to. Find your row.
Freelance writers, designers, and marketers
Your biggest risk is not a lawsuit. It is contractual warranty. Standard client agreements now include clauses like "Contractor warrants that all deliverables are original and do not infringe the intellectual property rights of any third party." If your deliverable is AI-generated, you cannot honestly warrant that in every case -- because you do not control the training data, and in the US you do not even hold copyright in the output.
Second risk: you may not be able to enforce your own work. If a client refuses to pay and republishes your AI-heavy deliverable without permission, your infringement claim may be weak on the AI-generated portions.
In-house content and marketing teams
Your exposure is organizational. If you publish AI-generated text about matters of public interest into the EU after August 2026 without disclosure and without documented human editorial responsibility, you have created a corporate fine exposure of up to 3% of global turnover. That is not a marketing problem. That is a board-level problem.
You are also the first line of FTC defense. Every AI-drafted claim about your product's performance needs substantiation, and "the model wrote it" is not substantiation.
Developers and product builders
If you ship a feature that generates text, images, audio, or video, you may be a "provider" under the AI Act, triggering Article 50(2) machine-readable marking obligations. If you fine-tune on scraped data, you inherit the input-side litigation risk directly.
If you are weighing whether your current technical skill set is the right long-term bet, the Career Pulse Score is a useful reality check -- it scores your role against automation and regulatory shifts rather than just buzzwords.
Agencies and consultancies
You are the indemnity sponge. Clients push AI risk down to you, and you push it to freelancers who cannot absorb it. The agencies that survive the next three years will be the ones that get specific about which models they use, what data those models were trained on, and how much of the deliverable is human-authored.
"We had a client pull a six-month retainer over a single AI-generated paragraph. Not because it was wrong -- because our contract warranted originality and we could not prove human authorship. That one clause cost us about $84,000 in annualized revenue. We rewrote every MSA in the following month and now we disclose model use at the top of every deliverable. It has never once lost us a deal. It has won us deals, because procurement teams trust the agency that volunteers the information first."
Your Compliance Checklist
Print this. Run it against every deliverable before it ships.
Before you publish
- Disclose model use where required. Any public-interest text published into the EU after 2 Aug 2026 needs an AI disclosure unless a named human holds editorial responsibility. Deepfakes always need disclosure.
- Name the human editor. Keep a timestamped record of who reviewed the content and what they changed. This is your Article 50(4) shield.
- Substantiate every factual claim. AI-drafted stats, comparisons, and performance claims need a source you can produce on demand.
- Score your copyrightable contribution. Was there substantial human selection, arrangement, or rewriting? If not, assume the work is unprotectable.
- Strip recognizable names, likenesses, and voices. Never generate content that imitates an identifiable person without written permission.
- Check your client contract for indemnity and warranty language. If it warrants originality, negotiate a carve-out for disclosed AI-assisted content.
- Document the model and version. Know what you used, when, and under what terms of service. Vendor terms shift, and your records are your defense.
- Run a defamation screen. Any output naming a real person or company gets human review, no exceptions.
- Keep the negative prompts and edit history. The trail from draft to published artifact is evidence.
Common Violations and What They Actually Cost
These are the patterns that show up over and over. Notice that most of them are procedural, not malicious.
- Publishing unsubstantiated AI-drafted claims. FTC civil penalties can reach into the tens of thousands per violation, plus mandatory compliance reporting and consent orders. DoNotPay's September 2024 settlement included $193,000 in relief plus injunctive terms.
- AI-washing -- overstating what your AI does. The SEC's March 2024 actions against Delphia and Global Predictions produced $400,000 in combined civil penalties for misleading AI claims. The SEC has kept AI-washing on its exam priorities list ever since.
- Failing to disclose AI-generated public-interest content in the EU. Article 99 penalties reach EUR 15 million or 3% of global annual turnover, whichever is greater.
- Using a cloned voice or likeness. Tennessee's ELVIS Act creates a private right of action with statutory damages. If the voice is recognizable, you are exposed.
- Registering AI-generated work and claiming full human authorship. The Copyright Office can cancel the registration. It has done so. Cancellation also destroys your ability to sue for statutory damages on the affected material.
- Training or fine-tuning on scraped protected data. The Anthropic settlement set the current benchmark at roughly $3,000 per work. Multiply that by your dataset size before you decide it is worth the risk.
Timeline of Key Regulatory Changes
Disclaimer
This article is general information, not legal advice. Nothing here creates an attorney-client relationship, and no article can assess the facts of your specific situation. Laws differ by jurisdiction, change frequently, and interact in ways that depend on your industry, your contracts, and where your audience lives. Consult a qualified attorney licensed in your jurisdiction before relying on any of this. The dates and figures reflect publicly available information at the time of writing and should be verified independently.
The Three Scenarios That Actually Break People
Abstract rules are easy to nod along to. Concrete failure modes are what change behavior. Here are the three that come up most often, and what the person involved wishes they had done differently.
Scenario 1: The warranty clause nobody read
A freelance copywriter takes on a 12-month retainer with a mid-size e-commerce brand. The master services agreement -- signed eight months earlier, unremembered -- contains a standard originality warranty. The writer uses an LLM for roughly 60% of first drafts, heavily edits them, and delivers on time for seven months.
A competitor notices a product description on the brand's site is nearly identical to one on their own site. Both were likely generated from similar prompts against similar training data. The competitor sends a demand letter to the brand. The brand forwards it to the writer and invokes the warranty.
What went wrong: the writer assumed "heavily edited" equals "original." Legally, that is probably true for the edited portions -- but the warranty covered the deliverable as a whole, and the writer had no record of which portions were purely generated. Without a record, the writer had no defense.
The fix: whenever you take on a contract with an originality warranty, either (a) negotiate an AI-disclosure carve-out, or (b) keep a version history that lets you identify the human-authored portions with precision. Most clients will accept (a) immediately. Almost none will push back on a clause that says "AI-assisted content will be disclosed at delivery."
Scenario 2: The compliance page that was not reviewed
An in-house content lead at a European SaaS company uses an AI tool to draft the company's summary of a forthcoming regulatory change. The article is published on the company blog, targeted at EU customers, and frames the company's product as the compliant solution.
After August 2026, that article is squarely within Article 50(4)'s scope: AI-generated or manipulated text published to inform the public on matters of public interest. No disclosure appears. No named editor is on record. The company's legal team discovers the gap during a quarterly compliance review.
What went wrong: the content lead treated the AI draft as a starting point and the human editing as sufficient. It probably is sufficient for the substance -- but Article 50(4) is not about substance. It is about whether a person or entity holds editorial responsibility and whether that responsibility is documented.
The fix: a two-line editorial policy. Every public-interest article carries a named responsible editor in the CMS metadata, and every AI-assisted article carries a short disclosure line. That is the entire compliance cost. It is trivial. Not having it is expensive.
Scenario 3: The course that hallucinated credentials
A solopreneur builds an online course on a regulated topic and uses AI to draft the marketing page and several lesson scripts. The AI generates a plausible-sounding statistic about industry outcomes and attributes it to a government agency that never published it. The AI also generates several curriculum claims that overstate what the course will qualify students to do.
This is a Section 5 problem, and if the course generates refunds at scale, a state AG problem too. The FTC has been consistent for two decades: unsubstantiated claims in advertising are deceptive, regardless of who or what drafted them.
The fix: every number in marketing copy gets a source link. Every qualification claim gets checked against the issuing body. And every AI-drafted claim gets the same scrutiny you would apply to a claim you wrote yourself -- because legally, you wrote it.
If you are a solopreneur building a portfolio of products, it is worth stepping back and asking whether your skill portfolio is durable or fragile. The Career Pulse Score at Workings.me is a quick, free way to pressure-test that.
Insider Tips From People Who Have Handled These Disputes
These are the practices that separate people who sleep well from people who get demand letters.
1. Disclose early and often, but calibrate the disclosure. Blanket statements like "this article was written by AI" are inaccurate and undermine you. Precise statements like "AI used for outline and first draft; final text written and edited by [name]" are accurate, defensible, and actually build trust with sophisticated buyers.
2. Treat the edit trail as a legal asset. If your CMS keeps version history, you already have most of what you need. If it does not, use a shared document with tracked changes before publishing. The point is not to prove you edited -- it is to prove what you contributed, because your contribution is your copyright.
3. Read vendor indemnities carefully. Several major AI vendors now offer IP indemnification for enterprise customers. Almost all of them condition it on using the vendor's built-in filters, not modifying outputs in certain ways, and not combining the model with other tools. If your workflow violates any condition, the indemnity evaporates. Many teams have indemnities on paper and none in practice.
4. Never let an AI tool give legal, medical, or financial advice under your brand. The liability flows to you instantly. If you must publish on a regulated topic, have a licensed professional review and sign off, and disclose their review.
5. Get an errors and omissions policy if you do client work. E&O coverage for content and marketing services is more affordable than most freelancers assume, and it is the difference between a bad month and an existential event. Check whether the policy excludes AI-related claims -- many older policies do, and you need a rider.
6. Register your genuinely human-authored work. If a work has substantial human authorship, register it. Registration is a prerequisite for statutory damages and attorneys' fees in US infringement suits under 17 U.S.C. Section 411. The registration does not have to claim the AI portions -- you can disclaim them explicitly, which is exactly what the Copyright Office guidance tells you to do.
7. When you get a demand letter, do not respond on the merits in the first 48 hours. Preserve everything -- prompts, outputs, version history, correspondence. Notify your E&O carrier immediately, because most policies require prompt notice. Then get counsel. The most common self-inflicted wound in these disputes is a defensive email that admits something the sender never knew.
8. Build a model register. If you are a team of more than three people, keep a simple internal list: which tools are approved, for what use cases, under what terms of service, with what indemnity. This document is what you show a client's procurement team, and it is what you show a regulator if asked. It takes an afternoon to create and it resolves most enterprise sales objections about AI.
The Five Questions That Resolve 90% of AI Legal Risk
When you are unsure whether something is safe to publish, run these. They are not a substitute for counsel, but they catch almost everything.
- Can I name the human who takes responsibility for this? If not, you fail the EU human-review carve-out and you have no internal accountability either.
- Can I substantiate every factual claim in this piece? If not, it is an FTC problem waiting to be triggered by a competitor's complaint.
- Did I contribute substantial human expression that is visible in the final work? If not, assume zero copyright protection and price your work accordingly.
- Does anything here imitate an identifiable person or a protected work? If yes, stop and get permission in writing.
- Does my contract warrant something I cannot prove? If yes, renegotiate that clause before you deliver, not after.
What Is Coming Next (And How to Prepare)
Three shifts are already in motion and will define the next 24 months.
Machine-readable provenance is becoming table stakes. Content credentials, watermarking standards, and metadata schemes are moving from optional to expected. The EU AI Act's Article 50(2) marking obligation is the first hard requirement, and it will not be the last. Expect procurement teams to start asking for provenance metadata the same way they now ask for SOC 2 reports.
The US is going state-by-state, not federal. California AB 2013 requires training-data transparency from developers whose models are made available to Californians, effective January 1, 2026. Texas TRAIGA imposes its own requirements from the same date. Colorado's AI Act has been pushed to mid-2026. If you sell nationally, you now have to comply with the strictest applicable state standard, which in practice means complying with California's.
Indemnity is becoming a product feature. In 2024, enterprise buyers asked vendors whether they would indemnify. In 2026, they ask which models are covered, under what filters, and up to what cap. If you are a service provider selling into enterprise, expect this to be a negotiation point in every deal. Build your position now: a list of the models you use, an honest statement of what you can and cannot warrant, and a clear disclosure practice.
The reframe that matters
Legal risk in AI content is not about whether you use AI. It is about whether you have a documented, defensible answer to the question "what did you contribute, and who is responsible for what you published?" Teams that can answer that question clearly are almost never in trouble. Teams that cannot are exposed regardless of how much or how little AI they use.
That is the whole game. Disclosure, substantiation, documentation, and a named human. Four habits. Everything else is detail.