Synthetic content: the liability underneath the feature
Generating voice, image, video and text is easy now. Underneath sits a stack of state statutes, open dockets, and an indemnity market still deciding what it covers.
This page is general information for operators, current as of the date shown. It is not legal advice, and reading it does not create an attorney-client relationship. Specific facts change the answer.
Who owns the output, and can you even promise that?
The Copyright Office's position is now explicit: output generated entirely by AI is not copyrightable, and writing prompts alone doesn't make you an author. Follow that into your own terms of service. The "you own the output" clause you inherited from somebody's template may be promising your customers ownership of something nobody can own. There are honest ways to draft around it, such as assigning whatever rights do exist and scoping your warranties to what you actually control. There are also drafting tricks that read beautifully right up until someone challenges them, and those are the ones that surface in a dispute, with your signature underneath.
The training-data cases, honestly
The litigation over model training is live and unresolved, so be careful with anybody who tells you it's settled in either direction. The first major merits ruling went against the AI company, with fair use rejected for training a competing product on protected content. That's one ruling, in one procedural posture, about one kind of copying. Here's what a downstream startup should take from it. Provenance questions stopped being hypothetical; they sit in diligence checklists now, and someone will ask you. And "the model vendor handles that" is true only as far as your contract with that vendor actually says so, which is usually less far than people assume when they say it.
The indemnity gap
Microsoft, OpenAI, Adobe and others offer copyright shields, and by offering them they set what your customers now expect from you. Read the conditions attached to those shields. They generally cover default products, unmodified, used as intended, which means fine-tuning, RAG pipelines, agentic workflows, and post-processed output commonly fall outside the protection. At the same time, insurers are filing generative-AI exclusions into standard policy forms. So when an enterprise customer asks you for Microsoft-grade output indemnity, there are two walls around what you can honestly sign: what your vendor actually gives you, and what your insurer actually covers. Find both edges before the redline call, not during it.
The deepfake patchwork
If your product touches faces or voices, start here. Federal law now criminalizes non-consensual intimate synthetic imagery and requires platforms to remove flagged content within 48 hours of notice, which makes it an engineering deadline as much as a legal one. Nearly every state has its own statute in this area, and roughly thirty of them regulate synthetic media around elections. Right-of-publicity and voice-cloning claims run alongside all of that. What you are really facing is a mapping problem, with your feature capabilities on one side and statute categories on the other. Solve it once at design time and you won't be relitigating it before every launch.
Provenance is becoming table stakes
California's transparency regime is operative for large providers, and it asks for three concrete things: provenance data embedded in the output, a public detection tool, and visible labels. Well below the statutory thresholds, C2PA-style provenance is turning into an enterprise expectation anyway, driven by buyers rather than by regulators. So if you generate content at any real scale, assume a customer will eventually ask how your output is marked, and make sure the answer you give is one your own engineers would recognize as true.
What to decide this quarter
None of this is an argument against shipping. It's an argument for shipping with the map open on the desk beside you.