OtterMind Krystian
Wydro
PL
a man in a cartoon setting where a little creature is eating the word AI
Knowledge base Guide: Law and AI

Copyright, deepfake
and AI in advertising

AI and copyright in advertising: who owns AI graphics, when a deepfake violates image rights, and what the AI Act requires. A guide with a checklist for agencies.

- AI Creative Director, OtterMind  ◆   ◆  8 min read
01 - The legality of AI in advertising

Is AI in advertising legal?

Yes, provided you check the input data, rights to the output, image rights of individuals, background trademarks, and the obligation to label content. Midjourney, ChatGPT, Flux or Sora generate materials in seconds that previously took days and cost thousands of zlotys to produce. Along with the speed came the question of the legal safety of the creative work.

During a webinar with Jacek Dwórznik (Regional Director at Shutterstock for Poland) and advocate Magdalena U. Miernik-Grzesiowska from Lookreatywni Law For Creatives, we discussed the most important pitfalls: image protection and deepfakes, copyright to prompts and graphics, the EU AI Act, and safe practices for agencies and marketers. Below you will find the essence of this knowledge, which is worth having before publishing your next AI creation.

AI Creative Talks: full live recording with advocate Magdalena U. Miernik-Grzesiowska and Jacek Dwórznik (Shutterstock), 1 h 51 min
02 - Input data (input)

What can you upload to AI models?

The generation process starts with input data: text prompts, reference graphics, PDF documents and voice samples. At this stage, three risks await.

Tool terms of service and model training

The free and basic plans of many generators reserve the right to use your prompts and files for further machine learning training. Uploading a confidential client brief, marketing strategy, source code or financial data can mean breaching a non-disclosure agreement (NDA) and losing a company secret.

For commercial tasks, choose Enterprise accounts or tools that opt-out of using data for training in their terms of service. This is a different condition from zero data retention, which means immediate deletion of data after processing. Always check separately whether the provider trains models on your data and how long they store it.

GDPR and personal data

Uploading employee photos, a mailing database or documents with client data to a generator constitutes processing of personal data within the meaning of the GDPR. If the provider has servers outside the EEA (European Economic Area) and you lack a signed Data Processing Agreement (DPA) with them, the company risks severe penalties.

The TDM exception in copyright law

Polish law, following the amendment to the Act on Copyright and Related Rights implementing the DSM Directive, includes the TDM (text and data mining) exception. This allows training models on publicly available works, provided the rightsholder has abstained from an opt-out reservation in a machine-readable format, for example in a robots.txt file or in metadata.

03 - Copyright for AI graphics

Does a prompt make you an author?

A prompt rarely makes you the author of a graphic. The most frequently asked question is: "Who owns the copyright to a graphic from Midjourney?". The answer depends on how much creative work a human contributes.

The creator is a human

According to Polish copyright law, a work can only be the result of individual human creative activity. Courts in the EU and the US rule similarly. A machine, algorithm or neural network model lacks legal personality, so they fall outside the definition of authors.

A prompt as a brief

Legally, a prompt is most often treated as an order or a brief given to a contractor, rather than a work. Even a highly complex scene description leaves this assessment unchanged:

  • pure AI output enters the public domain, meaning it falls outside copyright protection,
  • anyone can download such a graphic and use it themselves, and copyright law gives you zero grounds to prohibit its copying.

When does copyright protection arise?

Protection arises only when a human makes a significant, creative contribution of their own. Examples of such a contribution:

  • advanced photomontage in Photoshop,
  • complex post-production and combining multiple layers,
  • custom colour grading, retouching, collage or manual drawing of key elements.
04 - Deepfake and image rights

When does a deepfake violate image rights?

A deepfake violates image rights whenever the recipient recognises the person and you lack their consent. Deepfakes and voice cloning offer great possibilities in promotion, but they are subject to strict regulations.

The right to one's image

Article 81 of the Copyright Act requires the consent of the person depicted to distribute their image. It makes little difference whether you used a real photo or generated a digital double. If the recipient recognises the person, for example, a famous actor, influencer or friend, the image is being used.

A deepfake with a star, such as Tom Cruise or Robert Lewandowski, advertising a product lacking a licence and an advertising contract constitutes a direct violation of personal rights (Articles 23 and 24 of the Civil Code) and an act of unfair competition.

Voice is also protected

Cloning the voice of a voiceover artist or a celebrity in tools like ElevenLabs enjoys the same protection as a face. Polish courts recognise voice as a personal right subject to full legal protection.

05 - Trademarks in the background

How does AI weave in other people's trademarks?

Models have been trained on billions of images from the web, so they can 'draw in' protected trademarks or industrial designs in the background, even if the prompt omitted them. During the webinar, we discussed two clear examples:

  • Pac-Man: the prompt was about an 80s-themed party, and the AI wove characters from the cult game into a garland on the wall. Such a creation was unfit for commercial use.
  • Smiley Face: the yellow, smiling face is a trademark of The Smiley Company, registered in many classes of goods and services.

Trademark infringement occurs when the mark is used in the course of trade functioning as a trademark, meaning it can mislead regarding the origin of goods or services in a given Nice Classification class. Before launching a campaign, check the databases of the Polish Patent Office and EUIPO.

06 - The AI Act and content labelling

When does the AI Act require content labelling?

The AI Act distinguishes between the obligations of the tool provider and the entity publishing the content. The disclosure obligation for the publisher covers images, audio and videos meeting the definition of a deepfake. The method of disclosure depends on the application, and artistic works follow specific rules. The European Artificial Intelligence Act (EU AI Act) introduces transparency obligations:

  • Labelling deepfakes: if you publish video, audio or an image depicting existing people, objects, places or events that looks authentic and was generated or altered by AI, you inform the audience about the artificial origin of the content.
  • Machine marking (watermarking): AI system providers must mark generated content with machine-readable metadata, for example in the C2PA / Content Credentials standard.
  • Exceptions: for clearly artistic, creative, satirical or fictional works, the disclosure takes a limited form, tailored to the work and preserving the comfort of its reception. Discussing a specific case with a lawyer is highly recommended.
AI Act slide: when AI content labelling is required, and when it is exempt
AI Act: when you need to label AI content (based on European Commission icons)
07 - Contracts and checklist

How to secure contracts and creative work?

Agency contracts with clients

In the relationship between an agency or creator and a business client, precise wording in specific task contracts and the transfer of economic rights is what counts:

  • Scope of AI use: specify in the contract or brief whether and to what extent the project permits generative tools.
  • Declaration of authorship: opt out of standard clauses where the agency declares that 'the entirety of the work constitutes 100% a work within the meaning of copyright law subject to the transfer of economic copyrights' if the main motif was created in AI.
  • Guarantees and indemnification: use professional stock libraries with commercial AI, such as Shutterstock Generative AI. Shutterstock provides Human Review and offers a legal and indemnification guarantee that protects the licensee against third-party claims.

Checklist: 6 questions before publication

Before publishing an AI-based creation, answer six questions:

  1. Does the tool have a commercial licence and do the terms of service allow the use of graphics for profit-making purposes?
  2. Have personal data, client logos covered by an NDA or company secrets ended up in the prompt or attachment?
  3. Do the background and graphic details contain accidental logos, trademarks, protected architecture or registered designs?
  4. Does the character or voice resemble a real person who is yet to give formal consent?
  5. Does the photorealistic creation or deepfake feature clear information about the use of AI, in accordance with the AI Act?
  6. Is the client aware of the AI involvement and does the contract clearly regulate the legal status of the generated elements?

Safe commercial use of AI rests on three pillars: transparency, knowing the tools' terms of service, and verifying every generated piece of material.

Are you looking for safe AI solutions for your company or do you want to train your team in legal prompting and marketing creation? Contact me, and I will present AI implementation workshops and consulting.

Key Takeaways slide: six steps: tool and plan, input materials, result verification, risk and labelling, documentation, team rules
Six steps before publishing an AI creation (slide from the live session)

Who owns the copyright to a Midjourney graphic?

A work can only be the result of individual human creative activity, so pure AI output falls outside copyright protection. Protection appears only after a significant, creative human contribution, for example in a photomontage, post-production, retouching or manual drawing of elements.

Can I register an AI graphic as a company logo?

A pure AI graphic lacks copyright protection. If you combine it with unique typography and a company name, and the whole distinguishes goods or services, you can register it as a trademark with the Patent Office (UPRP or EUIPO).

Is a prompt 'in the style of [living artist's name]' legal?

An artistic style itself falls outside copyright protection. However, if you use an artist's name to create a direct market substitute for their works, it may be considered an act of unfair competition or a violation of personal rights.

What risks does a company face for an unauthorised deepfake?

The person whose image or voice was manipulated can demand the cessation of the infringement, removal of the material, a public apology, financial compensation and payment of a sum for a social cause. The company also risks an image crisis and sanctions under the AI Act.

Is the voice of a voiceover artist or a celebrity also protected?

Yes. Voice cloning in AI tools, such as ElevenLabs, enjoys the same protection as a face. Polish courts recognise voice as a personal right covered by full legal protection, so you need the consent of the person whose voice you are cloning.

When do I have to label content as AI-generated?

When you publish video, audio or an image featuring people, events or places that look authentic and were created or altered by AI. The AI Act then requires clear information for the audience. Exceptions apply to satire and parody, among others.

Can I upload a confidential client brief to an AI generator?

Free and basic plans often allow the provider to train models on your prompts and files, which can breach an NDA. For commercial tasks, choose Enterprise accounts or tools with training on your data opted out. Zero data retention is a separate condition: data deleted immediately after processing.