AI, Intellectual Property & Liability

Who owns what an AI makes, and who pays when it goes wrong

Author
Affiliation

Prof. Dr. Markus Oermann

THWS FIW

Published

July 23, 2026

The previous unit closed on a deliberate silence. The EU AI Act, for all its ambition, says nothing about who owns what an AI produces and nothing about who pays when an AI causes harm. It is product-safety and fundamental-rights law, not property law and not civil liability law. This final unit fills those two gaps. We first ask whether the output of a generative model can be owned at all, and on what terms models may be trained on protected material (intellectual property). We then ask who bears the loss when an AI-driven product injures someone (liability). Both questions expose the same underlying tension: a legal order built around human authors and human wrongdoers now has to accommodate systems that generate content and take decisions on their own.

2 Personality rights: the person behind the output

Even where copyright is silent, the person depicted or imitated is not without protection. Copyright asks whether an output is a protected work; personality rights ask whether it uses a real person’s identity without consent. A voice, for instance, is usually not a “work” (it is not a personal creation in the copyright sense), yet imitating a recognisable voice can still violate the speaker’s personality rights - at least in Germany with its broad, constitutional based version of a general personality right.

The point crystallised in 2024, when Scarlett Johansson objected that OpenAI’s “Sky” voice assistant sounded uncannily like her, after she had declined an offer to lend her voice. OpenAI withdrew the voice. The same concern drives the film and games industries, where actors fear being replaced by AI-made digital replicas, and where the likeness of deceased performers (the estate of Carrie Fisher, whose image continued to appear in the Star Wars franchise, is a much-cited example) can be reconstructed synthetically. Legislators have begun to respond directly. In September 2024 California passed statutes requiring an actor’s permission for AI-generated digital replicas of their likeness and the consent of the estates of deceased performers.

An AI voice assistant is trained to sound recognisably like a famous German actor who declined to license her voice. On what basis could she object in Germany, even though a voice is not a copyright “work”?

  • Copyright authorship, because she inspired the output
  • Personality rights, which protect a recognisable voice or likeness independently of copyright
  • The Product Liability Directive
  • Nothing, because AI output is always free to use

4 Closed catalogue versus fair use

Behind the TDM question lies a deeper structural difference between the two great copyright traditions, and it directly shapes how AI training is judged on either side of the Atlantic. EU copyright works with a closed catalogue of specific, enumerated exceptions (the limitations doctrine). Anything not expressly permitted stays forbidden; there is no general escape clause. Whether AI training is lawful therefore turns on whether it fits one of the listed exceptions, above all the Article 4 TDM exception and its opt-out.

The United States takes the opposite route. There is no closed list but a single open standard, the fair use doctrine of 17 U.S.C. §107, under which courts weigh four factors case by case: the purpose and character of the use (including whether it is “transformative”), the nature of the work, the amount used, and the effect on the market for the original. Whether training a model on protected works is fair use is being litigated across a wave of US cases and is far from settled. The comparison is instructive: the EU offers more ex ante certainty (a defined exception with a defined opt-out) at the price of rigidity, while the US offers flexibility at the price of unpredictability. For an AI developer, the EU asks “does an exception cover this?”; the US asks “would a court find this fair?”.

Practical takeaway for AI-generated content

If you want to create synthetic content with AI and possibly claim rights in it, three things follow from the law above. Check the provider’s terms and conditions to see whether the provider reserves any rights in the output. Do not assume you own AI output: on the prevailing view a routine prompt yields no copyright, so the output may be freely reusable by others too. And if you rely on the EU TDM regime as a rightholder, remember that your only real lever against commercial training is a valid, machine-readable reservation of rights.

5 Liability: who pays when an AI causes harm

5.1 Why the AI Act sends you elsewhere

Return to the silence we started with. Suppose an autonomously navigating warehouse robot with built-in AI injures an employee, and she wants compensation. She will not find her claim in the AI Act. The Regulation governs market access, risk management and supervision; it grants no claim for damages. It works only indirectly: if the manufacturer breached an AI Act duty, that breach may help establish that the product was defective or that a duty of care was violated. The claim itself lives in liability law, which comes in two shapes: strict (no-fault) liability and fault-based liability.

5.2 The reformed Product Liability Directive (EU) 2024/2853

The centrepiece of the EU’s answer is the reformed Product Liability Directive, Directive (EU) 2024/2853. Classic damages law struggles with “black box” AI: how do you prove a programming error caused the harm when the system learns on its own? Strict product liability sidesteps that. It does not attach to blameworthy conduct but to the source of danger the producer created. The injured party need not prove fault, only the defect and the resulting damage.

The decisive reform is one of scope: the Directive makes explicit that software, and therefore AI systems, counts as a product. A producer who puts defective AI software into circulation is liable, regardless of fault, for personal injury and property damage. The Directive must be transposed into national law by 9 December 2026. Its limits matter as much as its reach: it covers personal injury and property damage, not pure economic loss and not, in the ordinary case, discrimination, which is exactly where the second, fault-based track and its proof problems come back into play.

Strict liability (Product Liability Directive)

Liability that attaches not to fault but to the danger created by placing a defective product on the market. Under the reformed Directive (EU) 2024/2853, software and AI are products, so their producers are strictly liable for personal injury and property damage.

6 The withdrawn AI Liability Directive and the remaining gap

Alongside the product-liability reform, the Commission had proposed a second instrument on the same day in September 2022: the AI Liability Directive (AILD). It targeted the proof gap that strict liability leaves untouched, namely fault-based claims for harms such as discrimination or pure economic loss. It would have eased the claimant’s burden through a right to disclosure of the information documented under the AI Act and a rebuttable presumption of causation once an AI Act duty was shown to have been breached. That proposal was withdrawn in early 2025. The consequence is a lopsided landscape: strict liability for defective AI products is now firmly in place, but for fault-based claims outside the product-liability track, the injured party carries a demanding burden of proof, with no harmonised relief.

Which statement about civil liability for AI harm in the EU is correct?

  • The AI Act contains its own claim for damages against AI providers.
  • The reformed Product Liability Directive treats software and AI as products, so producers are strictly liable for personal injury and property damage.
  • The AI Liability Directive is now in force and reverses the burden of proof for all AI harms.
  • Strict product liability covers pure economic loss and discrimination.

7 Course wrap-up

With intellectual property and liability, the last two silences of the AI Act are filled, and the arc of this course closes. We began by asking what artificial intelligence is and why it demands ethical attention at all. We built the foundations of moral philosophy and probed agency, responsibility and the responsibility gap. We examined bias and discrimination, the data-protection regime that governs personal data and AI models, the transformation of the public sphere, and the sustainability and labour dimensions of the technology. We then moved from ethics to governance: ethics guidelines, internal codes and self-regulation, and finally the hard law of the EU AI Act. This unit added the two bodies of private law the Act deliberately leaves out.

The recurring lesson is that neither ethics nor law alone is sufficient. Ethical principles such as fairness, transparency and human oversight give us the vocabulary of what we owe one another; law turns a subset of those principles into enforceable obligations, claims and liabilities. But we have also seen the seams where the translation strains: an authorship regime built for human creators, an opt-out mechanism whose effectiveness is doubtful, a liability landscape left lopsided by a withdrawn directive. The work of this field, and increasingly of the engineers and lawyers who will shape AI, is precisely to keep closing that gap between what we value, what we can enforce, and what we actually build. That is where the responsibility, and the opportunity, now lies with you.

8 References

8.1 Literature

  • Fechner, F. (2026): Medienrecht. UTB.
  • Oster, J. & Busch, C. (2026): Integration von KI-Anwendungen in Suchmaschinen. die medienanstalten / ALM, June 2026, on the TDM opt-out and the reform debate around AI training.

8.2 Norms & Standards

  • Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market (DSM Directive), Arts. 3-4 (text and data mining). https://eur-lex.europa.eu/eli/dir/2019/790/oj
  • Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive). https://eur-lex.europa.eu/eli/dir/2024/2853/oj
  • Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive, AILD), COM(2022) 496 final, 28 September 2022; withdrawn in early 2025.
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689
  • Urheberrechtsgesetz (German Copyright Act), §2 (protected works), §44b (general text-and-data-mining), §60d (text-and-data-mining for research). https://www.gesetze-im-internet.de/urhg/
  • 17 U.S.C. §107 (United States Copyright Act, fair use). https://www.copyright.gov/title17/92chap1.html#107
  • California AB 2602 and AB 1836 (2024), on AI digital replicas of performers and of deceased performers.

8.3 Case law

  • Municipal Court of Prague, judgment of 11 October 2023 (published April 2024), the first ruling by an EU court on the copyright status of AI-generated output (DALL-E image; no copyright absent human creation).
  • AG München, 13.02.2026 – Az. 142 C 9786/25 - No copyright for AI generated Logos.