UK AI copyright rules explained for business owners

Person reviewing a printed document at a wooden desk with a pen, natural light from a window
TL;DR

UK businesses are governed by the Copyright, Designs and Patents Act 1988 on AI copyright questions, not a separate law. The real risk for owners sits in two places: what their teams feed into AI tools and what they publish from them. A 2025 government consultation is proposing new text and data mining rules that will change the legal landscape materially over 2025 and 2026.

Key takeaways

- There is no dedicated AI copyright law in the UK: the Copyright, Designs and Patents Act 1988 governs AI training data, AI-generated outputs, and the content you feed into tools. - As a business user, your practical exposure runs in two directions: the content your team pastes into tools, and the content you publish from them. The training-data dispute between AI companies and rightsholders is a separate legal battle. - Many licences for news databases, stock image libraries, and research subscriptions prohibit automated AI processing; breaching them exposes the business to contractual and copyright claims independently of each other. - Microsoft's Copilot Copyright Commitment provides indemnity for qualifying uses of Copilot; not all AI tools offer equivalent protection, and the scope varies widely. - A UK government consultation in early 2025 proposed a new opt-out text and data mining exception; draft legislation expected over 2025 to 2026 will change the legal landscape for training data and rights reservation.

A freelance designer in Bristol has been using Midjourney on client work for six months. A client asks who owns the final images. A solicitor in Leeds pastes a case summary into ChatGPT to speed up drafting, then wonders if the firm has breached its own data policy. An agency owner in Manchester sends an AI-drafted report to a corporate client who has just added a clause requiring confirmation that no AI tools were used on copyrighted third-party source material.

These are not edge cases. They are the conversations arriving now in owner-operated businesses across the UK, and the answers all trace back to the same piece of legislation passed before the internet existed.

The Copyright, Designs and Patents Act 1988 is the primary law governing AI and copyright in the UK. There is no dedicated AI copyright statute. The CDPA applies to training data, AI-generated outputs, and the content businesses feed into tools every day. Text, images, code, and music are protected by default, and copying them without permission or a recognised exception is an infringement.

One CDPA provision does acknowledge machine-made work. Section 9(3) provides copyright protection for “computer-generated works” where there is no human author, with the “author” being the person who made the arrangements for the work’s creation. That clause, written in the 1980s to cover plotter software and procedurally generated graphics, is now being stretched to cover AI outputs. How much human editorial input is needed to attract standard copyright protection, rather than the narrower 50-year computer-generated works term, remains unsettled in UK law.

The UK government ran a consultation on copyright and artificial intelligence from February 2025, overseen by the Department for Science, Innovation and Technology and the Intellectual Property Office. The consultation proposed new rules for text and data mining, transparency obligations on AI developers, and mechanisms for rightsholders to signal that their content is not available for training. Draft legislation is expected during 2025 and 2026. Until then, the CDPA as it stands governs this area.

Why does it matter for your business?

Two copyright exposures matter for owner-managed businesses. The first is what your team feeds into tools: pasting licensed or client content into a public chatbot can breach your licences and infringe copyright. The second is what you publish from them: AI-generated outputs may reproduce protected work, making you liable even if you did not know the model had trained on that material.

On the input side, the risk often sits in licences you have already signed. Many news databases, stock image libraries, and research subscriptions explicitly prohibit automated text extraction or third-party AI processing. Pasting an extract from one of those tools into a public chatbot may void your subscription terms and expose the business to a contractual claim, separate from any copyright action.

On the output side, the major AI vendors have taken different positions. OpenAI assigns users any copyright it holds in ChatGPT outputs and disclaims liability if those outputs infringe a third party’s rights. Microsoft’s Copilot Copyright Commitment goes further: it offers to defend qualifying enterprise customers and cover adverse judgments in copyright claims arising from Copilot output, provided users have kept the default content filters enabled. That protection is conditional and has scope limits. If you are using AI tools to produce client deliverables and have not read the IP terms, you are carrying risk you have not priced.

Where will you actually meet it?

The copyright question becomes concrete in four situations: client contracts specifying how AI tools may be used on their materials; vendor terms that describe training rights over your input content; professional indemnity claims where AI-generated advice turns out to be wrong or plagiarised; and supply chain audits from larger clients managing their own AI risk under new procurement policies.

The litigation already clarifying the landscape is significant. Getty Images sued Stability AI in the UK High Court in January 2023, alleging that millions of its images were used without licence or payment to train Stable Diffusion. Authors’ groups have filed suits in the US against OpenAI over book content used in GPT model training. Both cases signal that the training-data question is live and contested, even if final UK verdicts remain outstanding.

For business users rather than AI developers, the more immediate risk is in commercial transactions. A growing number of larger UK organisations are adding AI-specific clauses to their supplier agreements, asking service providers to disclose which tools they use and to confirm they have not processed client materials in unmanaged AI tools. If your firm uses AI in client delivery, these clauses will start appearing in your contracts. A short internal policy about which tools you use and on what material makes answering them straightforward.

When to ask vs when to ignore

You can largely set aside the training-data dispute: that argument is between AI developers and rightsholders, not between you and your clients. Your exposure as an owner-manager sits in three narrower areas: what your team puts into tools, what you publish from them, and what your contracts say. In many commercial situations, those three things can be managed without specialist legal advice.

Treat licensed content as sensitive. Instruct your team not to paste full documents from subscription databases, licensed image libraries, or client files into public AI tools unless the relevant terms explicitly allow it. For AI-generated text going into client work, run a quick check on phrases that feel distinctive and look for anything that appears to reproduce a known source closely. Image outputs carry higher risk: avoid prompting for known artists’ styles and check for embedded watermarks or logos.

For significant commercial work, keep a simple record of which tools you used and for what. Documentation of a reasonable process matters more than a perfect one if you ever face a claim.

The moment to involve a solicitor is specific: if a client contract requires you to warrant that your deliverables do not infringe copyright and you are using AI in delivery, get a short conversation with a commercial lawyer before you sign. For the day-to-day usage of mainstream enterprise tools such as Microsoft Copilot or ChatGPT Plus, good internal practice covers the risk without the overhead of legal advice.

What else sits alongside this?

UK AI copyright does not exist in isolation. UK GDPR and the Data Protection Act 2018 apply wherever your AI use involves personal data, independently of copyright. The EU AI Act, fully effective from 2026 to 2027, is influencing UK policy even though the UK is not bound by it. All three reinforce the same core discipline: know what you feed into tools and why.

The government’s 2025 consultation proposed a text and data mining exception that would allow AI developers to train on content they can lawfully access, unless the rightsholder has explicitly reserved rights using a machine-readable mechanism such as robots.txt. This mirrors the approach in Article 4 of the EU’s Digital Single Market Directive. A House of Lords vote in January 2025 backed amendments to the Data (Use and Access) Bill to strengthen copyright protections, 145 votes to 126. The outcome of that process will determine whether UK rightsholders end up with a meaningful opt-out or a narrower right than many expect.

For businesses that create intellectual property, design agencies, software houses, content studios, the practical implication is worth noting now. If the UK enacts an opt-out TDM regime, your website content could be used to train AI models unless you actively signal otherwise via robots.txt or metadata standards. The IPO’s January 2025 report confirmed that owner-managed businesses are materially affected by the current uncertainty. The safest working assumption for 2025 and 2026 is that existing CDPA rules remain in force, the training-data argument continues in the courts, and your practical risk stays where it has always been: what your team feeds in, what you publish out, and what your contracts commit you to.

Sources

- UK IPO (2025). Report on Copyright and Artificial Intelligence (CP2602959). The IPO's assessment confirming current UK law requires permission for commercial AI training and that owner-managed businesses are materially affected by the uncertainty. https://assets.publishing.service.gov.uk/media/69ba692226909a14239612e4/CP2602959_-_Report_on_Copyright_and_Artificial_Intelligence_web.pdf - UK Government / DSIT and IPO (2025). Copyright and Artificial Intelligence consultation. The February 2025 consultation proposing a new opt-out TDM exception and transparency obligations for AI developers. https://www.gov.uk/government/consultations/copyright-and-artificial-intelligence/copyright-and-artificial-intelligence - UK Parliament (1988). Copyright, Designs and Patents Act 1988. The primary UK legislation governing copyright, including section 9(3) on computer-generated works and the default protection for text, images, and code. https://www.legislation.gov.uk/ukpga/1988/48/contents - UK Parliament (1988). Copyright, Designs and Patents Act 1988, section 29A. The existing non-commercial TDM exception and its limits for commercial AI training use cases. https://www.legislation.gov.uk/ukpga/1988/48/section/29A - House of Commons Library (2023). Text and data mining and copyright. Background briefing on the UK TDM exception landscape, including the 2022 to 2023 government retreat from a broad commercial exception. https://commonslibrary.parliament.uk/research-briefings/cbp-9753/ - DLA Piper (2023). Generative AI and copyright: key issues for businesses. Legal analysis of copyright risks in AI-generated content for business users, including the significance of vendor IP indemnities. https://www.dlapiper.com/en/insights/publications/2023/04/generative-ai-and-copyright - AO Shearman (2023). Getty Images v Stability AI: what does it mean for AI and copyright? Analysis of the UK High Court case and its implications for training data practices and business exposure. https://www.aoshearman.com/en/insights/getty-images-v-stability-ai - European Parliament and Council (2024). Regulation (EU) 2024/1689 (EU AI Act), Article 53. Training data transparency requirements for general-purpose AI models, which are influencing UK policy thinking. https://eur-lex.europa.eu/eli/reg/2024/1689/oj - UK Music (2025). What Will The Government's Proposed Changes to the Rules on Copyright and Artificial Intelligence Mean for the UK Music Industry? Trade body analysis of the proposed opt-out TDM regime and the difficulties it creates for small creators and owner-run businesses. https://www.ukmusic.org/news/what-will-the-governments-proposed-changes-to-the-rules-on-copyright-and-artificial-intelligence-mean-for-the-uk-music-industry/ - Waterfront Solicitors (2024). Navigating AI and Copyright: what every UK business needs to know. Practitioner guidance on where copyright risk falls for UK business users, covering both input and output exposure. https://waterfront.law/navigating-ai-and-copyright-what-every-uk-business-needs-to-know/

Frequently asked questions

Who owns AI-generated content in the UK?

Under the Copyright, Designs and Patents Act 1988, computer-generated works carry a 50-year copyright term, with the "author" being the person who made the arrangements for the work's creation. For AI-assisted work generally, UK copyright in the final output depends on the degree of human creative input: editing, selecting, or structuring the material. OpenAI assigns users any copyright it holds in ChatGPT outputs but explicitly does not guarantee those outputs are free of third-party rights.

Can I paste client documents into a public AI tool?

Generally, you should not do so without checking both your client contract and the AI tool's terms. Client contracts often include confidentiality obligations covering automated processing. The tool's terms may reserve rights to use input content to train future models unless you are on an enterprise plan with that option disabled. Both issues create liability independent of copyright.

What is the UK text and data mining exception?

The UK has a text and data mining exception under CDPA section 29A for non-commercial research. A commercial TDM exception, proposed in the UK government's 2025 consultation, would allow AI developers to train on content they can lawfully access unless the rightsholder explicitly reserves rights via a machine-readable mechanism such as robots.txt. That exception does not yet exist; the consultation's outcome is expected to inform legislation during 2025 and 2026.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation