AI & Intellectual Property 2026 Comparisons

Last Updated September 02, 2026

Contributed By Sidley Austin LLP

Law and Practice

Authors



Sidley Austin LLP is an elite global law firm. With approximately 2,300 lawyers and 160 years of experience, the firm has established a reputation for innovative legal strategies to achieve powerful results for its clients in complex transactional, restructuring, crisis management, investigation, regulatory, and litigation matters. With 21 offices in major commercial and financial capitals worldwide, the firm’s lawyers possess the cultural awareness and legal acumen needed to advise clients in today’s global economy.

Under English law, there is no single comprehensive AI-specific IP legislation. Instead, matters relating to AI intersect with existing IP law and other areas such as data protection, product liability, export controls, consumer rights and employment.

UK intellectual property rights are primarily governed by existing case law and the following key statutes: the Patents Act 1977 (PA 1977), the Copyright, Designs and Patents Act 1988 (CDPA) and the Trade Marks Act 1994. Of these, the copyright provisions of the CDPA have been most relevant to AI matters.

Under English law, AI and IP law is influenced by international IP treaties, binding pre-Brexit EU legislation and case law persuasive post-Brexit EU case law, regional patent instruments, free trade agreements and soft-law initiatives. None creates a comprehensive AI-specific IP regime. Their influence is indirect – they determine which foreign works qualify for protection, constrain UK copyright exceptions for AI training, inform copyright and patent concepts, and shape current UK policy debates on transparency, licensing and AI-generated outputs.

International Treaties and Regional Instruments

The principal multilateral IP treaties to which the UK is a party are:

  • the Berne Convention;
  • the Paris Convention;
  • the Rome Convention;
  • European Patent Convention;
  • Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS);
  • World Intellectual Property Organization (WIPO) Copyright Treaty (WCT);
  • WIPO Performances and Phonograms Treaty (WPPT); and
  • Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP).

Assimilated EU Law

EU law remains influential but its status has changed post-Brexit. Much UK copyright and database law derives from EU directives (notably the InfoSoc, Software and Database Directives) and Court of Justice of the European Union (CJEU) decisions retained as assimilated law. However, under the Retained EU Law (Revocation and Reform) Act 2023, UK courts now have greater freedom to depart from retained CJEU case law.

Foreign Rights-Holders and Developers

Foreign AI developers are subject to the same substantive law as domestic developers, but the territorial nature of IP rights means training conducted wholly outside the UK may be difficult to challenge in UK courts. The EU AI Act has no direct effect in the UK, but UK developers placing general-purpose models on the EU market must, in practice, comply with its copyright policy and transparency obligations.

Under English law, the core IP statutes do not define “artificial intelligence”, “generative AI”, “foundation model”, “general-purpose AI model”, “training data”, “model weights”, “prompts” or “outputs” for substantive IP purposes. The UK has not enacted a cross-sector AI statute equivalent to the EU AI Act, so there is no statutory taxonomy of AI systems, and autonomous or agentic systems are not defined or treated as a distinct legal category.

UK IP law remains largely technology-neutral. There are, however, two relevant statutory definitions:

  • Section 178 of the CDPA defines “computer-generated” work as work “generated by computer in circumstances such that there is no human author of the work”. This definition is directly relevant to copyright authorship and duration for computer-generated literary, dramatic, musical or artistic works; and
  • Section 135(4) of the Data (Use and Access) Act 2025 (DUAA) defines “AI systems” as “machine-based system that, from the input it receives, can infer how to: (i) generate predictions, digital content, recommendations, decisions or other similar outputs; or (ii) influence a physical or virtual environment, with a view to achieving an explicit or implicit objective”. However, this definition is confined to the copyright and AI reporting provision in Section 135 of the DUAA and does not create a general IP taxonomy or alter the ordinary rules on subsistence, infringement, ownership or patentability.

The practical consequence of the absence of a detailed IP-specific taxonomy is that disputes are resolved by applying general, technology-neutral concepts to the facts of the relevant AI system and its use. In commercial practice, this also means that contractual definitions of models, weights, inputs, prompts, training data and outputs are likely to carry significant weight, particularly where statutory IP rules do not provide a bespoke answer.

There is no specialist AI court, tribunal or regulator in England and Wales. AI and IP issues sit with the bodies responsible for IP law generally.

Courts

IP claims are brought in the Intellectual Property List (“IP List”) of the Business and Property Courts, comprising the Patents Court and the Intellectual Property Enterprise Court (IPEC), a streamlined, costs-capped court with a small claims track. The leading case Getty Images (US) Inc v Stability AI Ltd [2025] EWHC 2863 (Ch) was decided at High Court level in the IP List.

Appeals are made to the Court of Appeal and Supreme Court. This includes the leading case Emotional Perception AI Ltd v Comptroller General of Patents, Designs and Trade Marks [2026] UKSC 3, which was decided by the Supreme Court.

The UK Intellectual Property Office

The UK Intellectual Property Office (UK IPO) examines and grants patents, trade marks and registered designs. It also hears proceedings (with appeals to the High Court or, for trade marks and designs, the “Appointed Person”) and leads IP policy. An “Appointed Person” is a senior intellectual property lawyer assigned by the Lord Chancellor to hear appeals from decisions made by the UK IPO relating to trade marks and registered designs. Claims for infringement of copyright and unregistered design rights must be brought through the High Court. The Copyright Tribunal has jurisdiction over collective licensing disputes, potentially relevant if collective licensing for AI training develops.

From an English law perspective, there is no sui generis IP right in an “AI system” as such. Protection is assessed component-by-component, using ordinary regimes for copyright, database right, patents, designs, trade marks and confidential information/trade secrets.

Source Code and Object Code

Under the CDPA a literary work is protected, which may include a computer program and preparatory design material. Source and object code are therefore protectable, subject to the usual subsistence requirements. However, copyright protects the code as written, not the underlying functionality, ideas, algorithms, language or data formats  (see SAS Institute Inc v World Programming Ltd [2020] EWCA Civ 599).

Model Architecture

Architecture is unlikely to be protected by copyright as such, which protects expression not abstract ideas, but its expression in code, configuration files, diagrams or documentation may be. The Supreme Court in Emotional Perception AI Ltd v Comptroller-General held that an artificial neural network is a “program for a computer” under Section 1(2)(c) of the PA 1977, but the claimed subject matter was not a computer program “as such” because it involved other technical means (a database, communications network and user device). Architecture may be patentable as part of a technical system or method, if other patentability requirements are met.

Weights and Parameters

This would be difficult to characterise as original copyright work (as generated through training, not authored) and unlikely to be patentable given weights/parameters are numerical values in isolation, though a system/method using trained weights may be. Usually protected through confidentiality, trade secrets and contract.

Embeddings

Individual embeddings are unlikely to attract copyright. Structured stores may attract database copyright or sui generis database right, though investment in creating data does not count – only in obtaining, verifying or presenting it (see British Horseracing Board v William Hill (Case C-203/02)).

Prompts

Protectable by copyright if sufficiently original and recorded; short functional prompts usually will not qualify. Longer system prompts, chains or curated libraries may be.

Fine-Tuning Materials, Training Datasets, Documentation and Evaluation Benchmarks

Certain materials may be protected copyright works; structured datasets may attract database copyright or database right. Database copyright depends on originality in selection/arrangement, not labour in creating data (see Football Dataco v Yahoo! (Case C-604/10)). If internal, protected via trade secrets and contract.

APIs and Interfaces

API code is protectable; API names may be trade marks; interface elements may attract copyright or design rights – but not functionality.

Scope of Software Copyright

AI software is protected like any other software. Source and object code are protectable as literary works, provided they are original as the author’s own intellectual creation. Computer programs fall within literary works under Section 3(1)(b) of the CDPA, and preparatory design material under Section 3(1)(c). Copyright protects expression, not ideas, procedures, methods of operation, algorithms, training techniques, mathematical concepts or functionality. In SAS Institute v World Programming, the Court of Appeal confirmed that replicating a program’s functionality, without copying code, does not infringe any copyright. Algorithms, training techniques and model architectures lie outside copyright, though detailed written architecture description is itself protectable against textual copying.

Prompts and System Instructions

Substantial, carefully crafted prompts and system instructions may qualify as literary works where recorded and reflecting free and creative choices. Curated prompt libraries may attract protection as compilations (under Section 3(1)(a) of the CDPA) or databases (under Section 3A of the CDPA). Short, functional or formulaic prompts are unlikely to clear the originality threshold. In practice, prompts are protected contractually and as confidential information.

Weights and Intermediate Artefacts

Copyright subsistence in weights, checkpoints and embeddings is doubtful, since they are generated by training rather than human-authored. A Section 9(3) computer-generated works argument is conceivable but untested. In Getty Images v Stability AI, the subsistence question was left undecided, though the High Court held that Stable Diffusion’s model weights did not store or reproduce training works and were not an “infringing copy” under Sections 22–23 and 27 of the CDPA. Getty obtained permission to appeal that aspect in December 2025, so the position may develop. Pending further authority, secrecy remains the primary protection strategy.

Limits on Protection

Beyond the idea/expression distinction, statutory limits in the CDPA include Section 50B (decompilation for interoperability, with strict conditions), Section 50BA (observing, studying and testing to determine underlying ideas), and Section 50A (back-up copies). These cannot be excluded by contract (as set out in Section 296A of the CDPA). Section 50C (copying for error correction) can be excluded by contract.

Section 29A permits copying for text and data mining for non-commercial research, notwithstanding contrary terms. Fair dealing exceptions (Sections 29 and 30) also apply to literary materials such as documentation and published prompts.

Copyright therefore meaningfully protects source code, object code, preparatory material, documentation, architecture descriptions, system instructions and original prompts – but not ideas, algorithms, methods or functionality.

AI inventions are assessed under the ordinary patentability requirements of the PA 1977, subject to the excluded-matter provisions of Section 1(2), which exclude mathematical methods and programs for computers “as such”.

Eligible Subject Matter

In Emotional Perception AI Ltd v Comptroller-General, the Supreme Court held that an artificial neural network (ANN) is a “program for a computer” because it is in substance a set of instructions causing a computer to process information in a particular way. However, the claimed invention was not excluded as a computer program “as such”. Applying the European Patent Office’s “any hardware” approach, it had technical character because the ANN could only run on hardware and the claims referred to a database, communications network and user device. The Court held that the Aerotel four-step approach should no longer be followed at this threshold stage. To note, this is not wholesale liberalisation – the “invention” threshold is a low hurdle, and claims must still satisfy novelty, inventive step, industrial applicability and sufficiency, with non-technical features filtered out.

Technical Effect

AI inventions are more likely patentable where the contribution is a technical application or improvement (eg, image/signal processing, robotics, cybersecurity, medical imaging). The specification should articulate the technical problem solved and how the AI features solve it (eg, reduced processor load, improved network performance), not merely that the model is “better” in the abstract.

Sufficiency and Disclosure

Section 14(3) requires disclosure enabling performance by the skilled person. Insufficiency is a revocation ground under Section 72(1)(c). Therefore, where the technical effect depends on training data, architecture, loss functions or hyperparameters, these may need disclosure, creating tension.

Does this Differ From Usual Protection?

Substantively, no – the same requirements apply, with no AI-specific threshold. The differences lie in application – ie, the excluded-matter provisions bite with particular force since an ANN is now characterised as a computer program. Sufficiency is distinctively challenging where training data cannot be deposited and may need to be kept secret.

Legal Framework

Protection arises under the Trade Secrets (Enforcement, etc.) Regulations 2018 (the “2018 Regulations”) and the parallel common law of breach of confidence (Coco v A N Clark (Engineers) Ltd [1968] F.S.R. 415). Information qualifies as a trade secret if it is secret, has commercial value because it is secret, and is subject to reasonable steps to keep it secret. The common law protects a broader class of confidential information, which matters for AI assets whose independent commercial value may be arguable.

Reasonable Measures

Reasonable measures are assessed contextually. Expected measures combine technical controls (tiered access, encryption of weights, API-only serving, monitoring for model/prompt extraction), organisational controls (classification policies, restricted repositories, training, offboarding) and contractual controls (confidentiality obligations and terms prohibiting reverse engineering, scraping and extraction). Releasing open weights generally destroys secrecy in the weights, though associated know-how may remain protectable.

Transparency Tensions

Confidential disclosure to regulators or auditors does not destroy secrecy (relative secrecy), though may become subject to requests under the Freedom of Information Act 2000 (FOIA) in which case the exemptions under Sections 41 and 43 FOIA become important to resist such disclosure. To note, the UK government declined to impose statutory transparency obligations in its 2026 Report.

Does this Differ From Usual Protection?

Not doctrinally – there is no AI-specific regime. The difference is practical. AI assets create distinctive secrecy risks, so “reasonable measures” include AI-specific controls.

Datasets, corpora, annotation sets, embedding stores and synthetic datasets may be protected, but there is no AI-specific database right; ordinary rules apply.

The sui generis database right under the Copyright and Rights in Databases Regulations 1997 arises where there is substantial investment in obtaining, verifying or presenting contents. Following British Horseracing Board v William Hill, investment in creating data does not count. This means synthetic datasets, model-generated labels and internally generated annotations may fall outside the right. However, investment in sourcing, cleaning, deduplicating, verifying, classifying, structuring or presenting pre-existing data may qualify.

Database copyright may subsist where the selection or arrangement is the author’s own intellectual creation (see Football Dataco v Yahoo!). Purely automatic assembly may fail, but expert-curated datasets may qualify. Original annotations may be literary works; embeddings individually are unlikely to attract copyright. Datasets may also be protected as confidential information/trade secrets and by contract.

Default Position

Assembling training, fine-tuning, retrieval-augmented generation (RAG), evaluation or safety-testing corpora commonly reproduces copyright works through scraping, downloading, storage, caching, deduplication, tokenisation and indexing. Each UK reproduction is prima facie a restricted act under Sections 16 and 17 CDPA unless licensed or covered by an exception. The exceptions are narrow: Section 29A (text and data analysis) requires lawful access and a sole non-commercial research purpose and Section 28A (temporary copies) is limited to transient, incidental copies with no independent economic significance. The UK has no broad commercial TDM exception or US-style fair use, and the 2026 Report confirms a broad opt-out exception is no longer the government’s preferred approach.

Getty Images v Stability AI

Getty abandoned its training and database claims (no UK training evidence), so the legality of training in the UK was undecided. On secondary infringement, the High Court held Stable Diffusion’s weights did not store or reproduce Getty’s works and were not themselves infringing copies. However, permission to appeal this was granted in December 2025 so this remains an unsettled area.

Areas of Certainty and Uncertainty

Reproductions made in the UK when assembling or processing a training corpus prima facie infringe copyright, unless licensed or covered by an exception. The principal TDM exception in Section 29A is limited to non-commercial research and does not provide a general safe harbour for commercial AI training.

However, significant uncertainty remains. Pending further case law or legislation, unlicensed commercial use of UK-protected works for AI training, fine-tuning, RAG corpus creation and related development activities remains high risk.

Pending Cases and/or Proposed Legislation

The Court of Appeal, in hearing Getty’s appeal, will test the High Court’s secondary infringement analysis, including the finding that an AI model can constitute an intangible “article” under the CDPA, but not an “infringing copy” – not whether AI training itself infringes copyright.

There is currently no pending legislation. The 2026 Report maintains the status quo: the government will not legislate until confident that reform will meet its objectives. Instead, it will gather evidence, explore a focused exception for particular uses, support licensing and transparency standards. At the same time, it will monitor litigation, EU case law and the licensing market. The 2026 Report also proposes removing Section 9(3) CDPA and announced a summer 2026 consultation on digital replicas (including a possible personality right).

Text and Data Mining

Section 29A CDPA permits copying for text and data analysis only where the user has lawful access and the analysis is for the sole purpose of non-commercial research, subject to sufficient acknowledgement. “Sole purpose” is a high hurdle. Terms restricting this exception are unenforceable, but to note that the UK has no rights-holder opt-out right unlike the broader EU Article 4 DSM exception. Additionally, the UK government’s previous proposal to introduce an opt-out exception covering text and data mining for any purpose (including AI training) was subsequently confirmed not to be the preferred way forward.

To rely on Section 29A CDPA, “lawful access” is important. Access via subscription, licence, institutional arrangement or genuinely open publication is the most clear and access by circumventing paywalls or technical protection measures is unlikely to qualify. Publicly available content subject to restrictive website terms is the difficult, untested middle case. Section 29A has no application to commercial model development or deployment, and research aimed at later commercial exploitation may also fall outside it.

Other Exceptions

Section 28A (temporary copies) requires transient or incidental copies with no independent economic significance and is rarely met by persistent dataset assembly, indexing or training. Fair dealing for research and private study (Section 29), quotation (Section 30) and caricature, parody or pastiche (Section 30A) are purpose-limited and do not map onto bulk ingestion, though pastiche has attracted academic interest. Educational (Section 32) and library/archive exceptions (Sections 40A–43) are institution- and purpose-specific. There is no US-style fair use.

Areas of Certainty and Uncertainty

The main certainty is the narrowness of the exceptions. Section 29A of the CDPA is limited to non-commercial research and lawful access; Section 28A of the CDPA is limited to transient or incidental technical copies; and the fair dealing, educational, library and archive exceptions are purpose-specific. None provides a defence for unlicensed commercial AI training, fine-tuning, retrieval corpus construction, product deployment or bulk evaluation on copyright works.

Pending Cases and/or Proposed Legislation

No pending case will determine these exceptions. The Getty appeal is focused on secondary infringement, and the training claims were not pursued. There is no pending legislation, though the 2026 Report will explore a focused exception. Practitioners should monitor the pending CJEU reference in Like Company v Google Ireland (Case C-250/25), which asks whether LLM training and chatbot outputs engage the TDM framework and the reproduction and communication rights. Post-Brexit, CJEU decisions do not bind the English courts, but may be persuasive.

Absent a commercial TDM exception, licensing is the most reliable route to lawful commercial training on UK-protected works. The 2026 Report introduced no statutory licence, compulsory licence or levy, recognising the licensing market as new and evolving and proposing no intervention at this stage.

Market Practice

The market is developing, fragmented and largely confidential. Reported deals are mostly bilateral, between large rights-holders and AI developers. Terms typically cover catalogue, permitted uses, duration, territory, fees, audit and reporting rights and warranties. Remuneration is not standardised and may include lump sums, annual or usage-based fees, or revenue-sharing.

Collective Licensing and Extended Collective Licensing

AI-specific collective licensing is developing (eg, the Publishers’ Licensing Services (PLS) is inviting publishers to opt in to an industry-led collective licensing initiative for generative AI). The UK extended collective licensing (ECL) framework under the Copyright and Rights in Performances (Extended Collective Licensing) Regulations 2014 allows licensing for non-members subject to safeguards, but no ECL schemes are currently authorised.

Statutory Mechanisms

There is currently no statutory or compulsory licence for AI training under UK law. The 2026 Report expressly states that there is no statutory licensing scheme for the use of copyright works to train AI models in UK law, and no UK precedent for a statutory copyright levy. 

No Statutory Opt-Out Regime

Because the UK has no broad commercial TDM exception, there is no statutory commercial opt-out. Rights are reserved by default, so a developer needs permission unless an exception applies. The EU DSM Directive’s Article 4(3) machine-readable reservation has no direct UK equivalent, though UK developers on the EU market may face EU AI Act obligations.

Legal Effect of Notices

Robots.txt, website notices, metadata, C2PA credentials and “do not train” signals are not self-executing IP instruments. However, they may matter as website terms may bind scrapers contractually and bear on “lawful access” under Section 29A. Similarly, notices may evidence knowledge relevant to secondary infringement and flagrancy/additional damages pursuant to Section 97(2) CDPA.

Autonomous Agents

The position should not materially change because the relevant act is performed by an AI agent as it is not a separate legal actor. The focus remains on the operator’s conduct, knowledge and control. An agent ignoring an encountered notice may worsen the operator’s evidential position.

Documentation Obligations

There is no general UK IP-specific statutory duty to document training data sources, filtering, deduplication, removal requests, rights reservations, synthetic data or model records and in the 2026 Report, the UK government declined to impose a statutory transparency obligation. Record-keeping incentives arise indirectly for, eg, from EU AI Act obligations for models on the EU market, UK GDPR accountability, licence warranties/audit rights and litigation-readiness.

Cross-Border Issues

Copyright infringement is territorial. The place of infringement is generally where the copy is made or stored (scraping infrastructure, cloud storage, training clusters, RAG indexes, caches, devices). In Getty Images v Stability AI, Getty abandoned its training claim as it could not establish UK training by Stability AI.

There is no AI-specific liability regime; ordinary principles of IP infringement apply. An AI system is not a legal person, so its acts are attributed to those who deploy, operate or cause them. Direct infringement is strict: intention and knowledge are irrelevant to liability, though relevant to remedies.

Copyright

To establish infringement, the claimant must prove subsistence, title, and a restricted act done (or authorised) in the UK involving a substantial part of the work. This is judged qualitatively with a causal connection. Scraping, dataset assembly, tokenisation, caching and loading works into memory during training or fine-tuning will ordinarily involve reproduction or transient copying. The 2026 Report also treats UK dataset assembly as likely to infringe unless excepted. Adaptation is relevant to computer programs. Communication to the public requires targeting the UK public. Database right catches extraction of a substantial part, including repeated extraction of insubstantial parts.

Territoriality and Proof

Each right is territorial. Getty’s training claims failed for want of evidence of UK training, and the High Court did not decide where cloud-based training takes place. Copying must be proved as fact, which is complicated by model opacity. Claimants rely on disclosure, memorised outputs, dataset documentation and distinctive artefacts (in Getty, reproduced watermarks). There is currently no pending case expected to resolve cross-border training. For patents, a Section 60(1) PA 1977 act in the UK must be established. For trade marks, liability generally requires use of the sign in the course of trade in the UK.

In Getty, the High Court held that the Stable Diffusion weights do not store the training works. Instead, they are the product of patterns learnt in training, not copies. So, the model was not an “infringing copy” within Section 27 CDPA. However, the decision is qualified in two ways: (i) the finding was confined to a diffusion model shown not to retain the works, but a memorising model could constitute an infringing copy; and (ii) the High Court’s conclusion that, although the model is an intangible “article”, it is not an “infringing copy” within Section 27 CDPA is currently under appeal.

Training and Inference Copies

These are separate from the weights. Embeddings, tokenised corpora, caches and checkpoints storing works can be Section 17 reproductions infringing unless licensed or excepted. Extracting database contents into a corpus can infringe database right irrespective of what the model retains.

Memorisation and De Minimis Copying

There is no AI-specific test in England and Wales. The ordinary substantial part analysis applies to outputs, judged qualitatively. So, short extracts can infringe while extensive but commonplace similarities may not (Infopaq). There is no separate de minimis doctrine and no regulator; these questions are typically proven by expert evidence in ordinary litigation.

Authorisation and Joint Tortfeasance

Supplying a tool capable of both infringing and lawful use is not, without more, authorisation under Section 16(2) CDPA where the supplier does not control its use (CBS Songs Ltd v Amstrad Consumer Electronics Plc [1988] UKHL 15). A provider is better placed where its terms prohibit infringement and it implements filters. It is worse placed where the service is designed to reproduce identifiable works or the provider controls generation and publication. Joint liability arises for procuring infringement or a common design (see Sea Shepherd UK v Fish & Fish [2015] UKSC 10). After Lifestyle Equities C.V. and another v Ahmed and another [2021] EWCA Civ 675, accessory liability requires knowledge of the essential facts making the primary act wrongful. There is no US-style vicarious copyright doctrine.

Secondary Infringement

Importing, possessing or dealing (under Sections 22–26 CDPA) requires knowledge or reason to believe the copy is infringing. Getty establishes that hosted access to a model located abroad is not importation. However, a local download could be, though the file must itself be an infringing copy. This distinction is now before the Court of Appeal.

Safe Harbours

The Electronic Commerce (EC Directive) Regulations 2002 defences cover information provided by service recipients. However, they do not cover training which is clearly conducted at the behest of the model operator. Although not binding, in Case C-188/24 WebGroup Czech Republic and NKL Associates and Case C-190/24 Coyote System the CJEU held that a provider exercising algorithmic control over content presentation may forfeit the hosting safe harbour.

Ordinary confidence and trade secrets law applies in England and Wales; there is no AI-specific regime.

Training, Prompting and Storage

Using confidential materials to train or fine-tune a model without authority would likely be unauthorised use of information imparted in confidence (Coco v A N Clark). For trade secrets, it would likely be unlawful use under the 2018 Regulations. An employee who pastes confidential information into a third-party model will usually be in breach. The same applies where an agent retrieves confidential material via tool calls or memory. Retention in vector stores, memory or logs can be continuing use, which confidentiality clauses should reach.

Model Outputs

A recipient of revealed confidential information with notice comes under an obligation of conscience, but liability for misuse generally requires knowledge (see Vestergaard Frandsen A/S v Bestnet Europe Limited [2013] UKSC 31). Further, a provider trained on misappropriated secrets may face injunctive relief once on notice. English law does not answer whether information a model infers (rather than reproduces) can be “acquired” unlawfully.

Proof and Pending Cases

The black box problem aggravates proof of use and derivation, so disclosure of corpora, prompts and logs is central.

Exceptions, Taking and Licences

There is no US-style fair use in England and Wales. The narrow CDPA exceptions also offer limited help: pastiche for style-emulating outputs, non-commercial TDM for research. The most important defences in practice are no substantial taking and independent creation. Similarities deriving from commonplace elements, unprotectable ideas or style can defeat the claim. Getty also shows that a model proved not to store the works cannot be an infringing copy.

Innocence, Limitation and Other Defences

Innocence is not a defence to primary liability but can limit damages (Section 97(1) CDPA; Section 62 PA 1977). Absence of knowledge answers secondary infringement and accessory liability after Lifestyle Equities. The limitation is six years, running act by act. Procedurally, territoriality challenges (as in Getty), strike-out where no UK act is pleaded and proportionate disclosure are significant.

There is no AI-specific rule: an output infringes if it reproduces, or communicates to the public, a substantial part of a protected work, with the necessary causal connection.

Outputs Similar to Training Works or Prompts

Where a model has memorised protected expression and an output reproduces it (verbatim text, image elements, watermarks), the output can infringe despite the copying being machine-mediated. Deliberate recreation of a work’s expressive composition can also infringe without literal copying (see Temple Island Collections Ltd v New English Teas [2012] EWPCC 1). Causal connection is established by the work’s presence in the training data. English law has no answer yet on who performs the restricted act (user, deployer or provider). Where a user supplies a work as a prompt and the output retains a substantial part, that would likely be copying by the user; uploading the reference work is itself a reproduction.

Imitation of Style, Genre or Voice

Copyright protects expression, not style or artistic voice. An output “in the style of” an artist taking no substantial part of any identifiable work is therefore unlikely to infringe for that reason alone.

Primary infringement is strict: a user who generates or publishes an output reproducing a substantial part of a protected work, or deploys an agentic system that carries out a restricted act, infringes regardless of intention or knowledge. Agent autonomy will not break attribution.

How Conduct Affects Liability and Remedies

Innocence can limit damages (Sections 97(1) and 233 CDPA; Section 62 PA 1977), though the risk of injunctive relief remains. Prompts engineered to elicit a specific work are powerful evidence of copying and flagrancy (and so potential additional damages). Documented human review and provenance checks can reduce risk. Provider indemnities do not typically affect liability to the right holder but can allocate risk.

Registered Trade Marks

Getty is the first substantive English judgment on this issue. Getty succeeded to a limited extent under Sections 10(1) and 10(2) of the Trade Marks Act 1994 for synthetic watermarks on generated images, where UK use was proved.  However, the problem was not shown to be widespread or persisting, and the Section 10(3) claim failed. Getty confirms that a model’s generation of a sign can, on appropriate facts, be used in the course of trade attributable to the service operator. A user who deliberately prompts a model to apply a third-party mark to marketed goods faces orthodox liability.

Passing Off, Endorsement and Advertising

Passing off is the principal vehicle for celebrity and personality cases. A false suggestion of endorsement is actionable (see Irvine v Talksport Ltd [2003] EWCA Civ 423; and Robyn Rihanna Fenty and others v Arcadia Group Brands Limited and others [2015] EWCA Civ 3), including by AI outputs imitating a recognisable voice, likeness or persona. However, there is no free-standing personality right and no general unfair competition tort in England and Wales. Imitating a brand’s style without misrepresentation is not actionable. AI-generated advertising remains subject to the CAP/BCAP Codes and the Digital Markets, Competition and Consumers Act 2024.

There are no AI-specific rules for patent, design and product-related infringement; ordinary infringement principles apply.

Patents

Making, using, importing or disposing of a product within a patent claim, or using a patented process, can be infringement under Section 60(1) PA 1977 even if the design, parameters or synthesis route were AI-generated. Indirect infringement under Section 60(2) (supplying means relating to an essential element, with knowledge) can also reach suppliers of software and components (see Menashe v William Hill [2002] EWCA Civ 1702). English law provides no answer on whether generating instructions amounts to supplying "means”. Instead, provider exposure is better analysed through accessory liability.

Designs and Software Code

Making an article to an AI-generated design producing the same overall impression as a registered design can infringe regardless of independent creation. AI-generated code can infringe copyright if it reproduces a substantial part of protected expression. However, the functionality of computer programs or programming languages are not generally protected (see SAS Institute v World Programming).

English law does not recognise an AI system as a legal actor and has no AI-specific attribution rules. An AI agent’s “autonomous” acts are typically attributed to those who deploy and operate it and prescribe its objectives, tools and permissions.

Principal Causes of Action

Scraping and retrieval would likely engage reproduction (Section 17 CDPA), database right, breach of website terms (which can restrict use even of unprotected databases: Case C-30/14 Ryanair v PR Aviation BV), removal of rights management information or circumvention of technical measures (Sections 296–296ZG CDPA). Transactional and design choices can commit the principal actor to patent and design infringement.

Originality standard

Copyright in AI-assisted outputs depends on whether the human user made free and creative choices expressed in the final work and it meets the “author’s own intellectual creation” standard. Copyright protects the resulting human expression, not the user’s idea, style or instruction.

Applying the Standard

A simple prompt is unlikely, by itself, to make the output human-authored, as expressive choices are made predominantly by the model. A more substantial contribution like detailed prompt engineering, iterative direction or selection and arrangement of permitted reference materials may support authorship, though protection may be limited to elements reflecting human creation.

Agentic Systems

With respect to agentic systems, autonomy weakens the case for human authorship. Where an agent decomposes tasks, generates its own prompts, uses its own chain-of-thought, selects its own tools and chooses outputs without meaningful human review, the creative link weakens. Human-designed, constrained and reviewed workflows may still support authorship; otherwise protection falls, if at all, within the computer-generated works regime.

Recognition

Section 9(3) CDPA provides that for a computer-generated literary, dramatic, musical or artistic work, the author is deemed to be the person who undertook the arrangements necessary for its creation. Section 178 defines “computer-generated” as generated by computer with no human author. English law thus recognises copyright in such works, but only within the ordinary framework and if the other subsistence requirements are met.

Ownership, Term and Scope

The deemed author of a computer-generated work is the person who undertook the arrangements necessary for its creation. Once the deemed author is identified, first ownership follows the ordinary rule in Section 11 CDPA (ie, the author is the first owner of copyright, subject to the employee-created work rule, assignment and any agreement to the contrary).

The term is shorter than for ordinary human-authored copyright expiring 50 years from the end of the calendar year in which the work was made. In terms of scope of protection, it is ordinary copyright except that moral rights (attribution and integrity) do not apply (Sections 79(2)(c) and 81(2)).

Unresolved Issues

Chiefly the originality paradox – Section 9(3) applies to works with no human author, yet originality requires the author’s own intellectual creation. It is also unclear who the person making the “arrangements” is, whether a prompt alone suffices, and developer/deployer/user priority in agentic systems.

Joint Authorship

Under Section 10 CDPA, joint authorship requires collaboration, an authorial contribution from each author and non-distinct contributions. In Kogan v Martin, the Court of Appeal held a putative joint author must contribute their own intellectual creation through free and expressive choices; mere ideas, corrections or suggestions do not suffice, though one need not “hold the pen”. An AI system cannot be one of the joint authors.

Derivative Works and Adaptations

English law has no US-style derivative-work category. The questions are whether a restricted act (eg, copying) has occurred. An AI output infringes if it reproduces the whole or a substantial part of protected expression and the English courts have stated that the test is qualitative rather than quantitative (see Designers Guild v Russell Williams).

Permissions and Ownership

Subsistence and infringement are separate questions. An output may attract copyright in new human-authored material yet still infringe an earlier work, meaning the creator may own the new original elements but be unable to exploit the output without the source owner’s permission. Permissions are traced to the protected expression’s source and third-party expression requires the source owner’s consent.

Copyright and Designs

There is no UK copyright register, so no registration-stage disclosure obligation arises. On enforcement, however, a claimant must prove subsistence, originality, authorship and title, so the extent of AI involvement may be central – particularly where human authorship is alleged or Section 9(3) is relied on. For registered designs, there is no general disclosure obligation, though computer-generated design provisions (untested for generative AI) may affect ownership.

Patents

There is no general requirement to disclose AI assistance. Section 13 PA 1977 requires identifying the human inventor(s) and, where relevant, deriving title. Naming an AI as inventor is impermissible (Thaler v Comptroller-General), and failure to identify a person may mean the application is treated as withdrawn. Incorrect inventorship may lead to correction, entitlement disputes or revocation, but there is no UK equivalent to US inequitable conduct.

Required Human Contribution

An AI system cannot be named as inventor, co-inventor or creator (Thaler v Comptroller-General of Patents, Designs and Trademarks [2023] UKSC 49).

For AI-assisted inventions, the inventor will be the natural person who actually devised the inventive concept – eg, the person who formulated the technical problem or configured or directed the AI. Merely owning the model, providing infrastructure or routinely validating results is insufficient. Where no human contribution rises to this level, there is an inventorship/entitlement gap and the government has declined to legislate on this so far.

Entitlement

Entitlement follows the ordinary rules. Inventors are the starting point, and a non-inventor applicant must show derivation of title. Employee inventions may vest in the employer under Section 39 PA 1977. For contractors and collaborators, entitlement depends on inventorship and contractual arrangements. AI platform terms cannot make an AI an inventor.

Skilled Person and Obviousness

Inventive step is assessed via the notional skilled person with the common general knowledge at the priority date. Where AI tools had become part of the skilled person’s routine toolkit, AI-assisted screening or optimisation may raise the obviousness bar. A routinely AI-generated candidate may lack inventive step if obvious to try with a fair expectation of success. But an AI’s ability to generate a candidate is not itself enough – inventive contribution may lie in problem formulation, dataset design, model configuration or recognition of unexpected significance. Emotional Perception AI Ltd v Comptroller-General confirms non-technical features cannot support inventive step.

Enablement and Sufficiency

AI does not alter the ordinary sufficiency requirement. Where the technical effect depends on training data, architecture or hyperparameters, these may need disclosure.

AI-Generated Prior Art

AI-generated disclosures and synthetic datasets can be prior art if made public before the priority date. Authorship by a human is not required. Ordinary filters apply – speculative, inaccessible or non-enabling machine-generated material carries limited legal effect where it would not genuinely inform the skilled person.

Registered Designs

AI-generated product configurations, graphical user interfaces (GUIs), icons, avatars and virtual goods may be protected as UK registered designs under the Registered Designs Act 1949 (RDA), provided they fall within the statutory definition of a “design” and satisfy the requirements of novelty and individual character.

A design is the appearance of the whole or part of a product resulting from features such as lines, contours, colours, shape, texture, materials or ornamentation. Registration protects appearance only and does not protect any aspect of the design’s functionality.

Registration lasts up to 25 years. Section 2(4) RDA provides that for computer-generated designs with no human author, the author is the person making the arrangements necessary for creation though this remains untested for generative AI. Ownership follows ordinary rules.

Unregistered Rights and Trade Dress

UK unregistered design right (Section 213 CDPA) protects original, non-commonplace shape/configuration (up to 15 years), with a computer-generated provision (Section 214(2)). It is a copying right. Supplementary unregistered design right protects appearance for three years but lacks a computer-generated provision. Registered designs are stronger, requiring no proof of copying. English law has no standalone trade dress right and get-up is protected via passing off or trade marks.

Trade mark law is generally indifferent to how a sign was created. An AI-generated name, logo, slogan, sound or motion mark can be registered under the Trade Marks Act 1994 if it is capable of clear and precise representation, distinctive, non-descriptive, not otherwise objectionable and not in conflict with earlier rights. There is no authorship requirement, so copyright and patent human-authorship issues do not arise at registration.

Ownership belongs to the applicant/proprietor, not the AI. The applicant must be a legal person using or intending to use the mark, and should ensure the correct entity files and that platform terms and assignments address underlying rights in artwork. The main risks are clearance and bad faith, so clearance searches remain essential.

The Statutory Moral Rights

The CDPA confers rights of attribution, integrity, false attribution and privacy. In the AI context, attribution and integrity rights are expressly excluded for computer-generated works (Sections 79(2)(c) and 81(2) CDPA), so Section 9(3) works carry no paternity or integrity rights. However, where a human author’s work is distorted or combined with AI output amounting to derogatory treatment prejudicial to honour or reputation, the integrity right may be engaged ordinarily.

False Attribution, Style and Synthetic Performances

The false-attribution right under Section 84 is increasingly becoming important due to AI development. Presenting AI output as a named creator’s work may be actionable. However, outputs merely imitating a creator’s style without copying protected expression or attribution usually infringe nothing, as style is unprotected. This is a recognised gap in the 2026 Report which proposes exploring this further through digital-replica/personality rights.

Synthetic performances raise performers’ rights, but these attach to actual performances – a wholly new AI-generated imitation of a voice or likeness is harder to challenge, so passing off, defamation, data protection and future digital-replica legislation may be more relevant.

English law recognises no free-standing image, publicity or personality right. A person does not have a proprietary monopoly in their name, image, likeness, voice or persona simply because it identifies them. Protection is instead a patchwork of IP, tort, privacy, data protection, consumer protection and criminal law claims.

Without registered trade mark infringement, passing off is the main commercial route for false endorsement or unauthorised merchandising, requiring goodwill, misrepresentation and damage. Performers’ rights under Part II CDPA may assist where an actual performance recording is copied, but there is a significant digital-replica gap, and synthetic performances imitating a voice or style without reproducing a recording fall outside them. Copyright may assist where a protected work is copied but does not protect voice, likeness or style as such.

Data protection may apply where name, image or voice is personal or biometric data. Misuse of private information, breach of confidence, harassment and defamation may also apply. For intimate deepfakes, criminal law (Section 138 DUAA) is increasingly relevant.

There is no separate forum for AI disputes.

Obtaining Evidence

There are no AI-specific mechanisms. Extended Disclosure under Practice Direction 57AD can target (with proportionate, issue-based requests and sampling for very large corpora):

  • training corpora and dataset manifests;
  • sourcing records;
  • model documentation;
  • fine-tuning and evaluation records;
  • prompts and outputs;
  • filter configurations;
  • tool-call histories;
  • API logs;
  • agent instructions;
  • memory stores; and
  • orchestration logs.

Patent-style tools adapt to supervised expert inspection of code, weights or pipelines, alongside agreed memorisation testing on the model.

Protecting Trade Secrets in Proceedings

To protect trade secrets, courts can order confidentiality clubs and rings limiting access to named external lawyers and experts (see OnePlus v Mitsubishi Electric [2020] EWCA Civ 1562).

The full injunctive toolkit applies; there are no AI-specific remedies. Interim relief is governed by American Cyanamid principles, and the court can in principle make each order contemplated, subject to proportionality, practicability and territorial limits.

Training, Dataset and Model Orders

Orders may restrain further reproduction of the claimant’s works in training, distribution of model weights into the UK (significant given Getty’s hosted access/download distinction) or provision of an infringing service to UK users; orders to remove works from datasets are conventional. Quarantine of model versions pending trial is available as preservation relief.

Output-Side, Intermediary and Ancillary Orders

Orders to disable identified outputs, implement filters or guardrails, suspend agents, revoke tool or API access, or disable autonomous publication or transaction functions are available, provided compliance is sufficiently certain. Other forms of relief include website blocking (Section 97A CDPA; Cartier International AG v British Telecommunications plc [2018] UKSC 28 for trade marks), delivery up and destruction, publicity orders and corrective statements. No English court has yet ordered model deletion or retraining; future training claims are the likely first test of “fruit of the poisoned tree” relief.

Monetary Remedies

A successful claimant can typically elect between damages and an account of profits. Damages are compensatory, usually assessed on the basis of lost profits, a reasonable royalty or the sum willing parties would have agreed (see Morris-Garner and another v One Step (Support) Ltd [2018] UKSC 20). Additional damages can be available for flagrant infringement (Section 97(2) CDPA), and the 2006 Enforcement Regulations require damages reflecting actual prejudice.

Non-Monetary Remedies and Cross-Border Issues

Final injunctions, delivery up and destruction (which, on Getty’s intangible “article” analysis, may extend to files, datasets and model copies), erasure and publicity orders and declarations can be obtained in certain circumstances. Model destruction or retraining is discretionary and untested. UK rights are territorial, but the English court can adjudicate foreign copyright infringement where it has personal jurisdiction (see Lucasfilm Limited and others v Ainsworth and another [2011] UKSC 39). The applicable law is that of the country for which protection is claimed. Money judgments may be enforced under the Hague Conventions or at common law.

Given the licensing-first environment, training and content licences carry particular weight. Key provisions include:

Scope and Permitted Uses

Precisely define the licensed rights (copyright, database right, metadata, annotations). Training, fine-tuning, evaluation, benchmarking, RAG/grounding, embedding generation, vector storage and agentic retrieval should be separately permissioned, since retrieval creates different risks. Identify permitted models/families, plus territory, term, infrastructure location, exclusivity and most-favoured nation protection.

Commercial and Control Terms

Remuneration may be lump sum, annual, usage-based, per-run, retrieval-based, revenue share or hybrid. Attribution should be tailored and will be more relevant where content is surfaced. Audit rights should be supported by logging of ingestion, filtering, opt-outs, training runs, versions, retrieval events and, for agents, tool calls, API access and autonomous publication. Control sublicensing, affiliate, customer and subcontractor access, with security/confidentiality terms.

Exit and Risk Allocation

The licence should specify the consequences of expiry or termination, including provisions on deletion or return of datasets, caches, embeddings and indexes and treatment of already-trained models (sunset, retraining, output filters). Warranties and indemnities should cover rights ownership, opt-out compliance and agent-mediated downstream uses.

There is currently no pending AI-specific legislation or regulation in the UK. The defining policy event is the UK government’s 2026 Report, which, although non-binding, marked a significant change in direction by confirming that the UK government’s previously preferred option of a broad commercial text and data mining (TDM) exception with a rights-holder opt-out was no longer its preferred way forward. However, the UK government has not reached a final position or ruled out future reform. Instead, it proposes further evidence-gathering, monitoring of litigation and international developments, and support for market-led licensing, technical standards and best practice on transparency.

Practically, right-holders retain existing rights but face enforcement/evidence problems against overseas-trained models and developers retain flexibility but face UK training risk.

The UK participates in international AI/IP co-ordination principally through soft-law, standards and policy rather than binding harmonisation – notably WIPO’s Conversation on IP and Frontier Technologies, plus the Council of Europe AI Convention, G7 Hiroshima Process, OECD, the Bletchley safety-summit process and standards work (AI Standards Hub, BSI). Trade instruments (CPTPP, UK-Singapore DEA) reinforce conventional standards without creating an AI-training regime.

The main divergence is copyright – the EU has TDM exceptions with rights reservation and the EU AI Act duties whereas the US relies on fair use litigation – the UK has none of these. As infringement is territorial, this drives regulatory arbitrage in where models are trained.

Sidley Austin LLP

Sidley Austin LLP
70 St Mary Axe
London
EC3A 8BE
UK

+44 20 7360 3600

clive.gringras@sidley.com sidley.com
Author Business Card

Law and Practice in UK

Authors



Sidley Austin LLP is an elite global law firm. With approximately 2,300 lawyers and 160 years of experience, the firm has established a reputation for innovative legal strategies to achieve powerful results for its clients in complex transactional, restructuring, crisis management, investigation, regulatory, and litigation matters. With 21 offices in major commercial and financial capitals worldwide, the firm’s lawyers possess the cultural awareness and legal acumen needed to advise clients in today’s global economy.