AI copyright indemnities are an enterprise tier
Copyright indemnities generally attach to enterprise and API plans and are conditioned on safety filters staying on. Verify your agreement, not a figure.
The sentence that shows up in procurement decks is some version of "the vendor indemnifies us, so the copyright risk is covered." It is worth pulling that apart, because in most of the cases where someone says it, three of the four load-bearing words are doing work they cannot support.
A copyright indemnity is a specific commercial product. It exists on specific plans, it runs in a specific direction, and it switches off under specific conditions. The version most teams believe they have is generally not the version attached to the account they are actually generating on.
What an indemnity is, and which way it points
An indemnity is a promise to defend and cover someone else's losses. In this context it means the provider agrees that if a third party sues you because of an output the provider's model generated, the provider will pick up the defence and the damages, within stated limits.
Two things follow immediately.
It is triggered by a third-party claim, not by a bad output. An indemnity does nothing about a deliverable that turns out to be off-brand, unusable or unprotectable. It is a litigation backstop, not a quality guarantee.
It does not make the output protectable. Where the human-authorship test fails, there is no copyright in the output for anyone to hold, and no indemnity changes that. Ownership, protectability and indemnification are three separate questions that share a paragraph in most vendor FAQs.
The direction matters too. Most consumer and mid-market platform terms contain an indemnity running from you to the platform, not the other way. Versely's terms include exactly that: the user agrees to indemnify and hold harmless the operating entity in connection with the user's use of the services, the user's content, or a violation of the terms. That is standard for a platform of any kind, and it is the opposite of the clause procurement thinks it is buying. Both can appear in the same document, which is how the misreading survives a skim.
Where indemnities actually sit
The pattern across the market as of August 2026 is consistent enough to plan around:
| Provider | Indemnity posture |
|---|---|
| Google, Microsoft, Anthropic | Copyright indemnities generally attach to enterprise and API tiers, conditioned on using safety filters. Not a consumer-plan feature. |
| Adobe Firefly | IP indemnification offered on qualifying commercial and enterprise plans. Caps and conditions are contract-specific. |
| Midjourney | Consumer-plan terms disclaim IP warranties. |
Three readings of that table are worth stating plainly.
The tier you are on is the fact that decides it. A vendor genuinely offering an indemnity on its enterprise contract is not offering it to a designer on a monthly consumer subscription, and the marketing page rarely makes that distinction as loudly as the contract does.
"Caps and conditions are contract-specific" is not a hedge, it is the actual state. For Adobe in particular, there is no published figure worth planning around. The number in your agreement is the number. If you cannot produce the agreement, you do not know what the cover is.
A disclaimer is information. When consumer terms disclaim IP warranties, the provider is telling you in writing that the infringement question is yours. That is a legitimate posture for a consumer product and a clear signal about which work belongs on which plan.
The conditions that switch it off
Indemnities that exist are conditional, and the conditions are the part that gets skipped. The recurring ones, in rough order of how often they are tripped:
- Safety filters must stay on. This is the most common condition and the easiest to breach without noticing, because the whole point of turning a filter down is to get an output the filter was blocking. Disabling or circumventing moderation typically voids cover for anything produced that way. If your team treats the safety checker as an obstacle rather than a term of the contract, the indemnity is decorative.
- You must not have prompted for it. Naming a protected character, a living artist's style or a specific trademarked property in the prompt is usually excluded. The indemnity covers the model surprising you, not you asking.
- The output must not have been modified into the problem. Cover generally attaches to the output as generated. Compositing a logo back in, or editing toward the thing the filter removed, moves the work outside it.
- Use must stay inside the licensed scope. An indemnity attached to a plan covers use permitted under that plan.
- Notice and control of the defence. Almost every indemnity requires prompt notice and gives the provider control of the litigation. Settle a claim yourself before telling the vendor and you may have forfeited the cover.
Any single one of these can turn a covered claim into an uncovered one, and none of them are visible from the plan comparison page.
The aggregator question
If you generate through a platform that routes to several providers, there are at least two agreements in play: the platform's, and the underlying model provider's. A platform reselling capacity is not in a position to hand you a provider's enterprise indemnity, because that indemnity was negotiated with the account holder, not with the account holder's customers.
This is why the model you choose is part of your rights posture rather than only a quality decision, and why treating a large model catalog as interchangeable is a mistake for high-exposure work. It is also why training provenance keeps mattering after you have a clean commercial grant — the case for making it a purchasing criterion is in licensed training data as a buying criterion.
Agencies carry this twice, because they sit between a provider and a client and often sign an assignment on one side that is broader than the grant they hold on the other. The structural version of that problem is in white-label AI content for agencies.
What to do instead of quoting a number
The failure mode is planning around a figure someone saw in a launch post. Replace it with four things you can actually verify:
1. Produce your agreement. Not the marketing page, not a summary, not the enterprise page for a plan you are not on. If nobody on the team can retrieve the executed contract, the honest position is that you do not know your cover.
2. Write down the conditions as an internal rule. "Filters stay on. No named IP in prompts. No compositing protected material back in." Three lines in the team handbook does more than a clause nobody has read. It belongs alongside the rest of your generation policy, per AI content governance for brands.
3. Match exposure to tier deliberately. Concepting, internal decks, organic social and pitch material are fine on terms with no indemnity. A national campaign is a different decision, and the sensible options are an enterprise agreement, a licensed stock or production route, or accepting the risk explicitly with someone senior signing it off.
4. Keep the record that makes a claim defensible. Model, version, date, prompt, account, plan. An indemnity claim is resolved with paperwork, and the paperwork has to exist before the claim does. Same record that answers every other rights question, which is the argument for capturing it once at generation time. The practical framing for client work is in legal and licensing basics for AI business content.
None of this is legal advice. It is the set of questions that makes a conversation with counsel short instead of forensic.
FAQ
Does an indemnity mean I cannot be sued?
No. It means that if you are sued on covered grounds, the provider defends and covers you within the contract's limits. You are still a defendant, you still have the disruption, and the cover still depends on you having met the conditions. An indemnity changes who pays, not whether the claim happens.
My plan does not include one. How exposed am I actually?
That depends almost entirely on what the output is and where it runs. An abstract background texture on an internal deck is close to zero risk. A generated character with a recognisable resemblance to a studio property, running as paid creative with a media budget behind it, is the top of the range. Sort work by exposure rather than by tool, and put the top of that range through a route where the risk is either covered or explicitly accepted.
Does turning off the safety filter really void it?
Where the terms condition cover on using safety filters, yes, and this is the condition most often breached in practice because bypassing the filter is the reason people bypass the filter. Treat filter settings as a contract term rather than a preference, and make that an account-level rule rather than a per-project judgement.
Should this change which model we use?
For high-exposure work, yes. Indemnity availability, training provenance and the licence terms attached to the output are three properties of a model that sit alongside quality and speed. For everything else, pick on output and cost as usual. The point is to know which bucket a brief is in before you start generating, not after the campaign is booked.