The AI copyright risk that is actually yours
Separate the lawsuits against the model labs from the two risks that reach a small business, then check whether the plan you pay for defends you or leaves the bill.
on this page · 0 / 0 checked
An authors’ class action against a model lab settles, and the number in the headline has ten digits [5]. Then you go back to the deck you are drafting in Claude, or the landing page copy ChatGPT wrote last night, and a smaller question sits underneath the work. You want to know whether any of that is yours, and who carries it if a rights holder ever objects to it. The reporting does not answer that, because the reporting is about a different question entirely.
That case is about how a lab obtained its training corpus. Your exposure starts much further downstream, at the file you send a client, and it lives in two contracts: the one you clicked through with your model vendor, and the one you signed with the client. This guide is for someone who bills for work an AI helped produce, which means copy, images, code, decks, research, voiceover. It is not for anyone training or fine-tuning a model on material they scraped, who needs a lawyer rather than a guide, and none of it is legal advice.
The case is about acquisition, not about output
Start with the settled one, because its shape is not what most summaries suggest. In Bartz v. Anthropic PBC, No. 3:24-cv-05417-WHA, the court-approved class notice describes the allegation as Anthropic having “infringed protected copyrights by downloading works in two allegedly pirated online datasets called Library Genesis (LibGen) and Pirate Library Mirror (PiLiMi)”, done “for purposes of training large language models (LLMs)” [5]. Under the settlement, Anthropic agreed to establish a non-reversionary Settlement Fund of “one-billion-five-hundred-million dollars ($1,500,000,000)”, which the notice estimates at “approximately $3,000 per work, prior to the deduction of any costs, fees, and expenses” [5]. Anthropic denies the allegations and argues that its use of the downloaded datasets was fair use [5].
Notice what the claim rests on. Not that a model learned from books, and not that its answers competed with the authors. The pleaded conduct is downloading, from named pirate libraries, under Section 106(1) of the Copyright Act, which gives a copyright owner the exclusive right to reproduce copies [5]. Whether a machine may learn from a book somebody lawfully bought is a genuinely unsettled question. Whether anyone may take a copy from a pirate mirror is not. The plaintiffs picked the settled one.
The class definition points the same way. A qualifying work has to have “an International Standard Book Number (ISBN) or Amazon Standard Identification Number (ASIN)”, to have been “registered with the United States Copyright Office within five years of the work’s first publication”, and to have been “registered before being downloaded by Anthropic, or within three months of the work’s first publication” [5]. That is a claim about a specific act on a specific date against a specific rights holder. You did not perform that act. It is not your case, and it will not become your case.
Two risks reach you, and they are not the same risk
The first is infringement in the output. A model reproduces protected expression closely enough that someone objects. What drives that risk is not how much text you generate but how recognisable the material is: song lyrics, a well-known code snippet, a logo, a photographer’s distinctive frame, a named artist’s style asked for by name.
The second is ownership, and it is the one people never see coming. You may not hold what you deliver in the way your client contract says you do. That risk arrives not as a letter from a rights holder but as a clause in a statement of work you already signed.
Both are about your outputs. Neither is about the lab’s inputs. They have different fixes, and mixing them up is why people either panic about the wrong thing or decide the whole subject is somebody else’s.
The agreement your seat sits under decides who pays the lawyer
Anthropic runs two separate contracts, and almost nobody checks which one they are under. The Consumer Terms of Service, effective 8 October 2025, cover “Claude.ai, Claude Pro, and other products and services that we may offer for individuals” [2]. They assign you output rights: “Subject to your compliance with our Terms, we assign to you all of our right, title, and interest—if any—in Outputs” [2]. They then disclaim everything around it, since “THE SERVICES, OUTPUTS, AND ACTIONS ARE PROVIDED ON AN ‘AS IS’ AND ‘AS AVAILABLE’ BASIS” [2]. And the protection runs the opposite way from the one you might assume: “YOU AGREE TO INDEMNIFY AND HOLD HARMLESS THE ANTHROPIC PARTIES FROM AND AGAINST ANY AND ALL LIABILITIES, CLAIMS, DAMAGES, EXPENSES” [2]. The same document states that “You are responsible for all Inputs you submit to our Services and all Actions” [2].
The Commercial Terms of Service, effective 17 June 2025, govern “Customer’s use of Anthropic API keys and any other Anthropic offerings that references these Terms”, and say directly that “Services under these Terms are not for consumer use” [1]. Section K.1 reverses the direction. Anthropic “will defend Customer and its personnel, successors, and assigns from and against any Customer Claim (as defined below) and indemnify them for any judgment that a court of competent jurisdiction grants a third party on such Customer Claim” [1]. A Customer Claim is defined as a third-party claim “alleging that Customer’s paid use of the Services (which includes data Anthropic has used to train a model that is part of the Services) in accordance with these Terms or Outputs generated through such authorized use violates any third-party intellectual property right” [1].
OpenAI draws the line in the same place and names the tiers, which makes it easier to check. Its Service Terms state that “OpenAI’s indemnification obligations to API customers under the Agreement include any third party claim that Customer’s use or distribution of Output infringes a third party’s intellectual property right”, and extend the same to Enterprise customers, a category the document lists as ChatGPT Enterprise, Edu, Healthcare and Business [3]. The individual subscription tiers do not appear on that list [3].
Anthropic’s commercial agreement does not name plan tiers at all. It attaches to API keys “and any other Anthropic offerings that references these Terms” [1], which means whether your seat is covered is settled by what that seat’s paperwork points at rather than by what you assume from the price. That is one support ticket with a documented answer, and it is worth having the answer in writing before the question is live.
The prices are public and low enough that cost is rarely the real reason anyone stays on the wrong contract. Claude Pro is “$17 Per month with annual subscription discount ($200 billed up front)” or “$20 if billed monthly”. A Claude Team standard seat is “$20 Per seat / month if billed annually” and “$25 if billed monthly”, for teams of 2 to 150 [8].
The exclusions describe an ordinary Tuesday
An indemnity is defined by its carve-outs, and these carve-outs are not edge cases. Anthropic’s Section K.3 removes cover where the claim arises from “modifications made by Customer to the Services or Outputs”, from “the combination of the Services or Outputs with technology or content not provided by Anthropic”, from “Inputs or other data provided by Customer”, from “use of the Services or Outputs in a manner that Customer knows or reasonably should know violates or infringes the rights of others”, and from “an alleged violation of trademark based on use of an Output in trade or commerce” [1].
Now read that against a normal working day. You paste a competitor’s page in and ask for something in that shape, which is customer-provided input. You take the draft and rewrite half of it, which is modification. You drop it into a template with a licensed font and a stock photo, which is combination. You ask for a caption in the style of a named living illustrator, which is the fourth one. You put the result on a product page, which is use in trade or commerce. The clause that scans as boilerplate is in fact a fairly precise description of the things that void the cover.
OpenAI spells out the mechanism more plainly. Its indemnity does not apply where “Customer or Customer’s End Users disabled, ignored, or did not use any relevant citation, filtering or safety features or restrictions provided by OpenAI”, where they “knew or should have known the Output was infringing or likely to infringe”, or where they “did not have the right to use the Input or fine-tuning files to generate the allegedly infringing Output” [3].
Microsoft is worth reading purely to see what “use the safety features” looks like once someone writes it down as a condition. Under the Customer Copyright Commitment, an Azure OpenAI customer generating text must have “the protected material text model … configured on in filter mode” and “the jailbreak model (i.e., Prompt Shield for jailbreak attacks) … configured on in filter mode”, must “include a metaprompt directing the model to prevent copyright infringement in its output”, and must have run evaluations “using tests designed to detect the output of third-party content”, with the report retained “and provided to Microsoft in the event of a claim” [4]. Those mitigations have been in force since 1 December 2023 [4].
You are not going to red-team your own newsletter copy, and nobody expects you to. The transferable part is the shape of the bargain. The indemnity is written for the customer who used the product as sold, left the filters on, and was not going looking for somebody else’s work. Every step you take away from that description is a step out of the cover, and none of those steps feel legal at the time.
Seats × per-seat monthly price × 12. Claude Team standard seats are $20 per seat per month billed annually [8]. Computed in the page; nothing is sent anywhere.
You own the output, and “own” is doing less work than it looks
Go back to the assignment language, in both contracts, and read the hedge. Anthropic assigns “its right, title and interest (if any) in and to Outputs” [1], and in the consumer version, “all of our right, title, and interest—if any—in Outputs” [2]. A vendor cannot assign you more than it holds, and what it holds in a machine-generated output is an open question that the parenthesis politely declines to answer.
The U.S. Copyright Office has answered its own part of it. In registration guidance published on 16 March 2023, the Office states that “copyright can protect only material that is the product of human creativity”, and that “if a work’s traditional elements of authorship were produced by a machine, the work lacks human authorship and the Office will not register it” [6]. Applicants must “disclose the inclusion of AI-generated content in a work submitted for registration and … provide a brief explanation of the human author’s contributions” [6]. Human authors can still claim the parts they made, where they “select or arrange AI-generated material in a sufficiently creative way” or “modify material originally generated by AI technology to such a degree that the modifications meet the standard for copyright protection” [6].
So the raw output is not property you can hand over in the way a client contract usually assumes. Your selection, arrangement and edits are protectable [6]. That is real, and it is thinner than a clean assignment of a finished work, and the difference only surfaces when it matters most: a logo somebody later wants to enforce, a character, a piece of music that gets licensed onward.
Two changes to your own paperwork close most of the gap and cost nothing. Say in the statement of work that AI tools were used in production, so the disclosure is a term you wrote rather than something a client finds out. And narrow the originality warranty from a flat promise that the deliverable does not infringe to a promise limited to your actual knowledge, which is the same standard your vendor already wrote into its own exclusion when it said “knows or reasonably should know” [1]. Warranting more than you can inspect is the part of the arrangement that has nothing to do with AI and everything to do with signing quickly.
What the law already requires a lab to publish
You do not have to negotiate for provenance information from a major lab, because for general-purpose models placed on the EU market some of it has to be public. Article 53(1)(c) of the AI Act requires providers to “put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790” [7]. Article 53(1)(d) requires them to “draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office” [7]. Those obligations have applied since 2 August 2025 [7].
The practical consequence for a small operator sitting anywhere in the world is that a copyright policy and a training-content summary are documents the provider is required to produce, and looking for them takes ten minutes. Do it before a model becomes load-bearing in client work, in the same spirit as skimming a subprocessor list before signing a data agreement. You are not auditing anything. You are checking that the answer exists and that it is not evasive.
Two questions are worth putting to your own vendor in writing, because the answers usually live in a support article rather than in the contract you accepted. Which agreement does my specific plan sit under, and does the output indemnity apply to the seat this work is actually being done on. If the second answer is no, that is a two-minute upgrade, not a project.
What still goes wrong
Terms move faster than guides do. Every date, price and quotation above was read from the source on 5 September 2026, and the two Anthropic contracts already carry effective dates under four months apart [1][2]. Re-read the one your plan sits under at renewal, and treat the specifics here as a snapshot to verify rather than a standing fact.
An indemnity is a defence, not an outcome. It means somebody else pays for the lawyer and the eventual judgment [1]. It does not stop a client pulling a campaign, does not undo the day you spend on it, and does not decide in your favour the question of whether an exclusion applies. That question gets answered afterwards, on the basis of what you knew or should have known at the time [1], about a prompt you probably did not keep. Keeping the prompt is cheap insurance and almost nobody does it.
The ownership gap is the one no checkbox closes. If your business depends on holding exclusive, enforceable rights in what you deliver, then AI-assisted production leaves you holding less than a hand-made version would, and the Copyright Office has said so about as plainly as an agency says anything [6]. For most client work that is fine, because most client work is bought to be used rather than to be defended. For the small share that is bought to be defended, the honest answer is to make more of it yourself, and no amount of reading a policy page changes that.
- 01Anthropic — Commercial Terms of Serviceanthropic.com
- 02Anthropic — Consumer Terms of Serviceanthropic.com
- 03OpenAI — Service Termsopenai.com
- 04Microsoft — Customer Copyright Commitment required mitigationslearn.microsoft.com
- 05Bartz v. Anthropic PBC (No. 3:24-cv-05417-WHA) — court-approved Class Noticeassets-us-01.kc-usercontent.com
- 06U.S. Copyright Office — Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence (Federal Register)federalregister.gov
- 07EU AI Act, Article 53 — Obligations for providers of general-purpose AI modelsartificialintelligenceact.eu
- 08Anthropic — Claude pricingclaude.com