Terms of use do not stop third-party claims
Provider terms allocate rights between you and the provider. A studio whose character appears in your output never signed them. Where the real exposure sits.
A contract binds the people who signed it. That sentence is unremarkable until you notice how much AI risk planning quietly assumes otherwise.
When a vendor's terms say you own the output and may use it commercially, they are resolving one relationship: yours with the vendor. Everyone else on earth retains whatever claims they had before you clicked accept. The studio whose character the model reproduced, the artist whose likeness surfaced, the brand whose trade dress appeared on a generated package — none of them are parties to your agreement, and nothing in it is enforceable against them.
This is not a gap a better vendor could close. No two parties can contract away a third party's rights.
The case that is about outputs
Most of the litigation coverage is about training, which makes it easy to read the whole field as a fight between rightsholders and model builders that users watch from the sidelines. One case breaks that framing.
Disney Enterprises, Universal and Warner Bros. v. Midjourney, consolidated in the Central District of California on 4 November 2025, targets outputs depicting protected characters, not only the training corpus. The matter is in discovery, with expert disclosures scheduled for October 2026, and no merits ruling exists. That timing matters: nobody gets to cite a holding here yet, in either direction.
What it establishes right now is narrower and more useful than a ruling would be. It establishes that major rightsholders consider the generated image itself to be the infringing artifact. If that theory is where the industry's attention is, the user who published the image is a more natural defendant than they were two years ago. The exposure is real and it is unresolved, which is a specific and awkward combination to sit in.
The equivalent dynamic on the licensing side, where a deal that looked like it would settle the question fell apart, is covered in the Disney-OpenAI deal collapse.
What has actually been decided, and how little of it helps
Here is the honest scoreboard as of August 2026. Every US decision below is district level. None is binding appellate precedent.
| Matter | Status | What it does for you |
|---|---|---|
| Bartz v. Anthropic (N.D. Cal.) | June 2025: training on lawfully acquired books held fair use; retaining a pirated library not fair use. Class settlement received final approval 20 July 2026. | Nothing directly. Settlements create no precedent, and the largest sums so far were paid over acquisition, not training. |
| Kadrey v. Meta (N.D. Cal.) | June 2025: summary judgment for Meta on training, expressly on a thin record, with the court signalling market-dilution theories could succeed if properly evidenced. Interlocutory appeal denied July 2026; the distribution phase is unresolved, hearing set 25 February 2027. | A defendant win that reads as an evidentiary comment, not a rule. |
| Thomson Reuters v. Ross (D. Del.) | February 2025: not fair use, for a non-generative legal research tool held to be a direct market substitute. On appeal; the Third Circuit heard argument 11 June 2026, decision pending. | This will be the first US appellate word on AI training and fair use. Until it lands, there is no controlling answer. |
| Getty v. Stability AI (England and Wales) | November 2025: Getty dropped the training and output claims mid-trial for want of UK territorial evidence; the secondary-infringement claim failed; an extremely limited trade mark win on watermarks. | UK training legality was never decided. Do not read it as a win for either side. |
| NYT v. OpenAI and Microsoft (S.D.N.Y.) | Discovery; a sanctions motion was filed in July 2026; no trial date. | Pending. Nothing to cite. |
The pattern is worth stating outright: one district win each way, the first appellate ruling still pending, and the biggest cheque so far written over how books were obtained rather than what was done with them. Anyone telling you the training question is settled is describing a case they have read the headline of.
Where your exposure actually sits
Strip out everything that is a fight between rightsholders and model builders, and four categories of user-side risk remain. These are the ones that survive a clean vendor agreement.
1. Output that reproduces protected expression. A generated frame containing a recognisable character, a distinctive costume, an identifiable set or a signature design is the clearest exposure. It does not require you to have intended it, and it is the specific theory the studio litigation is testing.
2. Trade marks and trade dress. Logos, packaging silhouettes, brand-defining colourways and product shapes are a separate body of law from copyright, with its own tests and its own claimants. A model that puts a plausible soft-drink can in shot has created a trade mark question, not a copyright one.
3. Likeness and voice. The fastest-moving area, and the one with the most jurisdictional variation. There is no federal right of publicity in the US, roughly fifty divergent state regimes, and live First Amendment tension over expressive uses. The state of that map is in voice and likeness law for creator marketing, and the direction it is heading is in digital replica rights are turning into property.
4. Downstream distribution. You are usually the one who published, ran the media, and made the representations to the client. Platforms and clients both have contractual routes to push a problem back to you regardless of how the underlying legal question resolves.
Notice that none of these are affected by an assignment clause. Notice also that the fourth one arrives first in practice: the thing that actually happens on a Tuesday is a takedown, a paused listing, or a client asking for a warranty you cannot give — not a federal complaint.
What actually reduces it
Five practices, in descending order of how much difference they make relative to effort.
Do not prompt for it. The largest single reduction in output-side risk is not naming protected characters, living artists, franchises or brands in prompts. This is also the condition most indemnities are built on, so it is doing double duty. Make it an account-level rule rather than a per-project judgement.
Leave the safety filters on. Same reason. Filter settings are a term of most agreements, not a preference, and a bypassed filter is the fastest way to move an output outside whatever cover you have.
Review outputs against a brand and IP checklist before publication, not after. Character resemblance, logo fragments, recognisable packaging, real-person likeness, on-screen text that looks like a mark. Five minutes per asset. The structured version of that pass is in auditing generated output against a brand manual, and the vocabulary for the risk categories is in brand safety.
Sort work by exposure. Concepting, internal material and organic social absorb risk cheaply. A national campaign with a media budget behind it does not. Deciding which bucket a brief is in before generation is worth more than any amount of cleanup after.
Keep the generation record. Model, version, date, prompt, account, plan. A third-party claim is answered with paperwork that has to exist before the claim does, and it is the same record that answers clearance and disclosure questions. The operational shape is in AI content governance for brands.
None of this is legal advice. It is the set of habits that keeps a claim from being unanswerable, and it costs almost nothing when it is built into the workflow instead of bolted on afterwards. Broader background on the whole risk surface sits in the AI copyright and safety guide.
FAQ
If a vendor indemnifies me, is this solved?
Partly, and only within the contract. Indemnities generally attach to enterprise and API tiers, come with conditions, and are triggered by a claim rather than preventing one. You remain the defendant. And the cover typically evaporates if you prompted for the protected material or bypassed the filters, which are exactly the routes by which most output-side problems arrive.
Has any court held that a user is liable for an AI output?
Not on any of the matters above. The studio case against Midjourney is testing an output-based theory but is in discovery with expert disclosures scheduled for October 2026 and no merits ruling. The correct statement is that user-side exposure is real and unresolved, and anyone claiming a holding either way is describing something that has not happened.
Does removing the asset fix the problem?
It reduces ongoing exposure and it is usually the right first move, but it does not undo a period of publication or the commercial use during it. It also does not address contractual promises already made to a client. Take it down, then work out what you warranted to whom.
What is the single most useful change to make this week?
A written prompt policy that bans named IP, characters, franchises and living artists, applied across the team. It is cheap, it is enforceable, it removes the largest category of output-side risk, and it is a precondition for most indemnities being worth anything.