Human Oversight in AI: Principles, Risks & Best Practices
Learn what human oversight in AI means, why it matters, key risks, EU AI Act requirements, oversight models, best practices,...
Learn how generative AI copyright applies to AI outputs, ownership, human authorship, training data, infringement, liability, and US and EU rules.
Generative AI copyright is not one legal question. It involves several separate issues: whether AI-assisted material qualifies for copyright protection, who may own any copyright that exists, whether copyrighted material can lawfully be used in an AI workflow, whether an output infringes third-party rights, what contractual rights apply, and who may ultimately face liability.
The most important distinction is:
Copyrightability ≠ copyright ownership ≠ infringement ≠ contractual rights ≠ liability
For example, an AI-assisted image may contain enough human-created expression to qualify for copyright protection while still raising a separate infringement question if it reproduces protected material from another work. Similarly, an AI provider's contract may give a customer permission to use an output without establishing that every element of that output qualifies for copyright protection under applicable law.
The legal position also varies by jurisdiction and remains unsettled in important areas.
In the United States, the current position of the U.S. Copyright Office is that copyright can protect qualifying human-authored expression in AI-assisted works, but purely AI-generated material does not become copyrightable simply because a user provided prompts. The Office's January 2025 Part 2 report explains that human-created selection, arrangement and modification can qualify where ordinary copyright requirements are met.
AI training raises a different question. U.S. fair use under 17 U.S.C. § 107 requires a fact-specific analysis rather than creating a blanket rule that all AI training is either lawful or unlawful.
In the European Union, Directive (EU) 2019/790 contains text-and-data-mining exceptions subject to conditions including lawful access and, under Article 4, rights reservations. Separately, Article 53 of the EU AI Act imposes copyright-policy and training-content transparency obligations on providers of general-purpose AI models.
A practical way to analyse generative AI copyright is:
Training → Model → Output → Human/business use
This is an issue-spotting framework, not a statutory legal test.
At the training or input stage, copyrighted books, images, articles, software, music and other works may be reproduced, extracted or uploaded. Questions can arise about authorization, licensing, lawful access, statutory exceptions and rights reservations.
At the model stage, the analysis may concern how protected material has been processed and whether legally relevant reproductions occurred.
At the output stage, the question may shift to whether generated text, images, code or other content reproduces protected expression.
Finally, at the human or business-use stage, users may select, edit, combine, publish, license, distribute or commercialize the output. Those acts can create additional copyright and contractual questions.
Before asking whether AI content is "copyrighted" or "legal," consider these questions:
What copyrighted material entered the workflow?
What creative contribution did a human make?
Does the resulting material qualify for copyright protection?
If copyright exists, who owns it?
Does the output reproduce protected third-party expression?
What do provider, employment and licensing contracts say?
Which jurisdictions apply?
How will the output be published, distributed or commercialized?
This framework helps prevent a common mistake: assuming that ownership automatically answers infringement.
It does not.
Under the current U.S. Copyright Office position, copyright may protect human-created expression in an AI-assisted work, but it does not arise merely because a person caused an AI system to generate content.
The Office's Copyright and Artificial Intelligence, Part 2: Copyrightability concludes that existing copyright principles can protect human-authored elements expressed through creative selection, coordination, arrangement or modification of AI-generated material. The Office also concluded that the mere provision of prompts, using the technologies it evaluated, does not itself provide sufficient human control over expressive elements to establish authorship.
Federal courts have also addressed human authorship.
In Thaler v. Perlmutter, the U.S. Court of Appeals for the D.C. Circuit affirmed the refusal to register an image that the applicant said had been created autonomously by an AI system. The court's March 18, 2025 opinion in Thaler v. Perlmutter affirmed the Copyright Office's decision on the facts presented.
The U.S. Supreme Court later denied Stephen Thaler's petition for certiorari on March 2, 2026. That denial left the D.C. Circuit judgment in place but did not constitute a separate Supreme Court ruling on the merits. The status can be verified on the Supreme Court docket for Thaler v. Perlmutter.
The case should not be read as establishing a fixed numerical threshold for human involvement in every AI-assisted work.
The relevant distinction is not simply whether AI was used.
Consider a hypothetical marketing designer who develops an original concept, generates several candidate images, selects particular components, rearranges them, manually redraws important portions, adds original typography and substantially edits the final composition.
That workflow presents a different copyrightability question from entering a prompt and publishing an AI-generated result without meaningful human alteration.
The U.S. Copyright Office does not use a percentage-based test for this distinction. The nature of the human creative contribution matters.
The U.S. position should not be treated as a worldwide rule.
EU copyright law uses concepts including the author's "own intellectual creation," while the application of authorship and ownership rules may also depend on the particular type of work and national copyright law.
The EU AI Act does not create a special EU-wide copyright for autonomously generated AI outputs. Businesses therefore should not assume that a conclusion based on U.S. law automatically applies in the EU or another jurisdiction.
Copyright ownership should normally be considered only after determining whether copyright exists in the material at issue.
Under U.S. law, copyright ordinarily vests initially in the author or authors of a protected work, subject to rules including work-made-for-hire arrangements and transfers of rights.
In AI-assisted business workflows, ownership may therefore depend on who supplied the copyrightable human expression, whether the work was produced within employment, whether a work-made-for-hire rule applies, whether rights have been assigned or licensed, and which jurisdiction governs the issue.
AI provider terms create another layer. They may address rights to inputs, outputs, commercial use, licences, restrictions and data use.
However:
Contractual output rights ≠ statutory copyright ownership
A contractual provision cannot by itself make material copyrightable if applicable copyright law does not recognize sufficient authorship.
Not automatically.
A prompt may contain considerable creative direction. It can describe subject matter, tone, composition, sequence, characters or other desired features.
But the current U.S. Copyright Office position is that prompts alone generally do not provide sufficient human control over the expressive elements generated by current systems to establish authorship.
Additional human selection, arrangement, editing or modification may lead to a different analysis.
Similarity does not automatically establish infringement.
The analysis may involve which elements of the original work are legally protected, whether copying occurred, the nature and extent of any reproduced expression, and whether an applicable exception or defence applies.
An independently generated work therefore presents a different question from an output that reproduces substantial protected expression.
Likewise, imitation of a general artistic style should not automatically be equated with copyright infringement. Other laws may become relevant depending on the facts, but style and copyright infringement are not synonymous.
Copyrighted material can technically be included in AI training. The legal question is whether the relevant reproduction, extraction or other use is authorized or permitted under applicable law.
There is no universal rule that "training on copyrighted works is legal," and no universal rule that it is automatically infringement.
Relevant factors can include the source of the dataset, lawful access, applicable licences, copyright exceptions, rights reservations, the jurisdiction, how copies are made and retained, how the material is processed, and whether protected expression is subsequently reproduced.
U.S. copyright law does not contain a general statutory exception specifically authorizing AI training.
One of the central issues in current litigation is fair use.
Under 17 U.S.C. § 107, courts consider four factors: the purpose and character of the use, the nature of the copyrighted work, the amount and substantiality used, and the effect on the potential market for or value of the copyrighted work. The statute does not make any single factor automatically decisive.
The U.S. Copyright Office's Part 3 report on generative AI training similarly rejects a categorical answer. As of October 2026, the Office continues to identify Part 3 as a pre-publication version and states that a final version will be published without substantive changes expected to its analysis or conclusions.
Recent litigation shows why AI training cannot responsibly be reduced to a single rule.
In Bartz v. Anthropic, the district court treated different copying activities differently. It held that reproductions of the named plaintiffs' books used in the LLM training process were fair use on the summary-judgment record, while Anthropic's acquisition and retention of millions of books obtained from pirate libraries raised a separate issue that was not justified merely because some books were later used for training. The case subsequently settled, and the court granted final settlement approval on July 20, 2026. The settlement did not convert the earlier district-court reasoning into a nationwide rule governing all AI training.
In Kadrey v. Meta, Meta obtained summary judgment on the plaintiffs' training-related fair-use claim based on the evidentiary record before that court. The decision emphasized the significance of market-harm evidence rather than establishing that all unlicensed AI training is fair use. The Kadrey v. Meta fair-use order is therefore best understood as a case-specific ruling.
A particularly important development arrived on September 29, 2026, when the U.S. Court of Appeals for the Third Circuit decided Thomson Reuters v. ROSS Intelligence.
ROSS had used Westlaw headnotes in developing an AI-powered legal research product. The Third Circuit affirmed the conclusion that ROSS's use was not fair use. However, the court expressly distinguished ROSS's system from generative-AI models. ROSS's product was a non-generative legal-search system rather than a general-purpose generative model. The Third Circuit's opinion in Thomson Reuters v. ROSS Intelligence is therefore important AI-training precedent, but it does not establish that training a generative AI model on copyrighted material is categorically infringing.
The correct U.S. conclusion remains narrow:
Fair use in AI training is fact-specific, and current cases do not establish one universal rule for all models, datasets and training practices.
The EU has an express statutory framework for text and data mining.
Article 4 of Directive (EU) 2019/790 requires Member States to provide an exception or limitation for reproductions and extractions of lawfully accessible works and other protected subject matter for text and data mining.
However, Article 4(3) provides that the exception applies only where the relevant use has not been expressly reserved by rightsholders in an appropriate manner. For material made publicly available online, the Directive specifically identifies machine-readable means as an example of an appropriate reservation.
This produces two important distinctions:
Publicly accessible ≠ automatically unrestricted
and
Lawful access ≠ automatic entitlement to every form of reuse
Article 3 contains a separate TDM framework for qualifying research organisations and cultural heritage institutions conducting scientific research under the conditions specified in the Directive.
A useful review sequence is:
Source → Access → Licence → Exception → Rights reservation → Processing → Output → Jurisdiction
Changing one part of that chain can change the legal analysis.
Training and outputs are separate copyright issues.
Even where a particular training practice is lawful, a specific output may create a different infringement question.
Potentially higher-risk outputs can include verbatim passages, near-verbatim text, substantial pieces of software code, recognisable components of copyrighted images, lyrics, or other protected expression.
Whether a particular output infringes copyright depends on applicable law and facts. The mere fact that AI produced the material does not resolve the issue.
Close resemblance may justify further review, but resemblance alone is not a legal conclusion.
The analysis may need to separate protected expression from ideas, concepts, genre conventions, commonplace elements, methods and stylistic characteristics.
Businesses can also create copyright issues through their inputs.
For example, an employee may upload a licensed research report, paid article, customer source code, commercial photograph or unpublished document into an AI service.
Relevant questions may include whether the organization owns the material, what the applicable licence permits, whether authorization has been obtained, whether a statutory exception applies, and whether separate confidentiality or data-use restrictions exist.
Public availability should not be treated as equivalent to unrestricted permission.
Commercial use is not automatically unlawful.
Under U.S. fair-use law, commercial purpose is relevant to the first statutory factor, but it is not independently conclusive.
However, publication at scale can increase practical consequences if problematic material is distributed widely. Businesses may therefore apply stronger review to marketing, advertising, publishing, client deliverables, software, product content and other paid creative work.
There is no universal rule automatically assigning copyright responsibility to the user, model developer, provider, deployer or employer.
Potentially relevant actors can include model developers, AI providers, application developers, deployers, businesses, employees, users and other participants in the AI value chain.
The analysis can depend on the jurisdiction, alleged legal theory, conduct, authorization, knowledge, control, causation and specific facts.
For a broader discussion of responsibility across AI systems, see AI liability.
User conduct may become relevant where a person uploads protected material, specifically requests reproduction, modifies generated material, circumvents restrictions, or publishes and commercializes an output.
Whether that activity creates liability still depends on the applicable law and facts.
Provider-side issues can involve separate conduct, including dataset acquisition, copying during model development, operation of the service, output behaviour and technical controls.
The different reasoning in Bartz, Kadrey and ROSS illustrates why provider responsibility cannot be reduced to one rule.
A company can create downstream copyright risk even where it did not develop or train the model.
For example, it may upload third-party copyrighted material, instruct employees to generate particular content, incorporate generated material into commercial products, or distribute an output to clients.
Vendor contractual protections can allocate risk between contracting parties, but they do not necessarily determine statutory rights or third-party infringement claims.
An AI system is technology. Legal responsibility is determined under the applicable legal framework.
A practical sequence is:
Actor → Conduct → Right or duty → Causation → Defence → Applicable law
The EU AI Act adds specific copyright-related obligations for providers of general-purpose AI models.
Those obligations should not be indiscriminately applied to every organization or employee that merely uses a generative AI tool.
Article 53(1)(c) of the current consolidated EU AI Act on EUR-Lex requires GPAI-model providers to put in place a policy to comply with Union copyright and related-rights law and, in particular, to identify and comply with rights reservations expressed under Article 4(3) of Directive (EU) 2019/790.
Article 53(1)(d) separately requires providers to prepare and make publicly available a sufficiently detailed summary of the content used to train the model, using a template supplied by the AI Office.
These requirements became applicable to GPAI providers on August 2, 2025. The European Commission explains that providers of models placed on the EU market before that date generally have until August 2, 2027 to meet the relevant GPAI obligations.
The Commission also confirms that use of its training-content summary template is mandatory under Article 53(1)(d), whereas adherence to the GPAI Code of Practice is voluntary. Its official GPAI obligations guidance and training-content summary guidance explain those distinctions.
For the wider regulatory context surrounding these obligations, see AI laws and regulations.
The critical distinction is:
AI Act compliance ≠ universal copyright clearance
The AI Act establishes regulatory obligations. It does not create a general copyright exception allowing GPAI providers to use any protected material they choose.
Nor does publishing the required training-content summary automatically establish that every copyright-relevant act in the training process was lawful.
The underlying copyright analysis remains governed by EU copyright law and, where relevant, applicable national rules.
This table is a high-level comparison. Specific disputes require jurisdiction-specific analysis.
|
Issue |
United States |
European Union |
|
AI-generated output |
The current Copyright Office position requires sufficient human authorship for protectable expression. |
The AI Act does not create a special copyright for AI-generated outputs; established copyright principles remain relevant. |
|
Human contribution |
Human selection, arrangement or modification may qualify; prompting alone does not automatically establish authorship. |
EU copyright concepts include the author's own intellectual creation, with application depending on the work and governing law. |
|
AI training |
Fair use under §107 may apply depending on the facts; there is no general AI-training exception. |
Directive 2019/790 contains statutory TDM exceptions subject to specified conditions. |
|
Rights reservations |
No equivalent federal statutory framework corresponding to Article 4(3). |
Article 4(3) allows rightsholders to reserve rights against use under the general TDM exception. |
|
GPAI-specific copyright obligations |
No direct equivalent to Article 53 of the EU AI Act. |
Article 53 requires GPAI providers to maintain a copyright-compliance policy and publish a training-content summary. |
|
Current uncertainty |
Fair-use treatment of generative-AI training and output-related disputes continues to develop through litigation. |
Interaction among TDM rules, rights reservations, AI Act requirements and national copyright law remains context-specific. |
For a wider jurisdictional comparison, see global AI laws.
Professionals who want a broader understanding of AI legislation, liability, privacy, regulation and governance can also explore AI Law & Regulation Essentials Training as an educational next step.

The following measures are practical governance and risk controls. They should not be treated as universal statutory requirements.
They can also form part of broader AI compliance considerations.
An organizational AI policy can identify approved tools, permitted uses, restricted material, copyright responsibilities, review expectations and escalation processes.
The objective is not to prohibit every uncertain use. It is to distinguish routine uses from situations that need additional scrutiny.
Before putting third-party material into an AI system, ask:
Where did this material come from, and what rights do we actually have?
Relevant considerations may include copyright ownership, licence terms, customer agreements, database restrictions, confidentiality provisions and whether machine processing is permitted.
The intensity of review can reflect the risk of the use case.
For higher-value public or commercial content, reviewers may look for unexpected quotations, distinctive passages, recognisable artwork, source code, logos or other content that appears to reproduce protected material.
Businesses should consider provider provisions dealing with inputs, outputs, commercial use, licences, restrictions, data use, retention and indemnities where relevant.
A provider saying that a customer "owns" an output should not automatically be interpreted as a guarantee that every element qualifies for statutory copyright protection.
Where ownership of AI-assisted work matters commercially, organizations may consider retaining drafts, revision history, source files, human edits and records of important creative decisions.
Such documentation may help demonstrate the role of human authorship.
It does not guarantee copyright protection.
Additional legal or specialist review may be appropriate where the output is a significant commercial asset, exclusive ownership is important, a client requires clear intellectual-property rights, an output appears to reproduce third-party material, copyrighted datasets are being used systematically, or licensed content has restrictions on machine use.
Not every routine AI use requires legal review. Escalation should be proportionate to the circumstances.
Before publishing or deploying AI-generated material:
Identify the AI system and how it is being used.
Identify copyrighted material entering the workflow.
Confirm appropriate rights to uploaded material.
Review relevant provider terms.
Identify the jurisdictions involved.
Check outputs for possible reproduction of protected expression.
Identify meaningful human creative contributions.
Review significant commercial publication or distribution.
Document important human edits and decisions where useful.
Escalate uncertain or higher-risk cases.
These are practical issue-spotting steps rather than a statement that every item is legally mandatory in every situation.
Generative AI copyright becomes easier to analyse when the legal questions are separated.
Start with the workflow:
Training → Model → Output → Human/business use
Then ask:
Is the material copyrightable? Who owns any rights? Has protected expression been infringed? What contractual rights apply? Who may bear legal responsibility?
Those questions can produce different answers.
Recent U.S. litigation reinforces the point. Bartz distinguished LLM training from the separate acquisition and retention of pirate-source books before the litigation later settled. Kadrey turned heavily on the evidentiary record presented to the court. And on September 29, 2026, the Third Circuit rejected fair use in Thomson Reuters v. ROSS Intelligence while expressly distinguishing ROSS's non-generative system from generative-AI cases.
The EU uses a different legal structure. Directive (EU) 2019/790 provides text-and-data-mining rules, including the Article 4 rights-reservation mechanism, while Article 53 of the EU AI Act creates additional copyright-policy and training-transparency obligations for GPAI providers.
None of these developments supports a simple universal statement that "AI content is copyrighted," "AI training is legal," "AI training is infringement," or "AI Act compliance clears copyright risk."
The more reliable approach is to identify the relevant material, actor, conduct, right, jurisdiction and downstream use at each stage of the AI workflow.
Professionals who want to strengthen their broader understanding of AI legal and regulatory issues can explore AI Law & Regulation Essentials Training.
This article provides general educational information and does not constitute legal advice. Copyright and AI regulation can vary by jurisdiction and change over time. Organizations should obtain appropriate legal advice for specific circumstances.
It can depend on the jurisdiction and the level of human creative contribution. In the United States, the current Copyright Office position protects qualifying human-authored expression in AI-assisted works but does not treat purely AI-generated material as copyrightable merely because a person supplied prompts.
First determine whether copyright exists. If qualifying copyrightable authorship is present, ownership may then depend on the human creator, employment rules, work-made-for-hire principles, assignments, licences, contracts and applicable law.
Not automatically. The current U.S. Copyright Office position is that prompts alone generally do not provide sufficient control over generated expressive elements to establish authorship using the technologies it evaluated.
Potentially. The legality of particular uses depends on jurisdiction, source, licensing, copyright exceptions, rights reservations and the way material is processed. U.S. fair use is fact-specific, while EU law contains statutory text-and-data-mining provisions subject to conditions.
Commercial use is not automatically unlawful. Businesses may still need to assess copyrightability, infringement, licences, contractual restrictions and other applicable laws.
Potentially. An output that reproduces protected third-party expression can raise infringement issues. Similarity alone, however, does not determine the legal result.
There is no universal answer. Developers, providers, deployers, businesses, users or other participants may become relevant depending on their conduct, the applicable legal theory and jurisdiction.
Article 53 requires providers of general-purpose AI models to maintain a policy for compliance with EU copyright and related-rights law, including relevant Article 4(3) rights reservations, and to publish a sufficiently detailed training-content summary using the required template.
The United States currently relies heavily on human-authorship principles and fact-specific fair-use analysis. The EU combines its established copyright framework and statutory text-and-data-mining provisions with specific AI Act obligations for GPAI providers.
Useful controls include approved-tool policies, input-rights checks, human review of outputs, provider-term review, documentation of significant human creative contribution and escalation of higher-risk commercial uses.
Learn what human oversight in AI means, why it matters, key risks, EU AI Act requirements, oversight models, best practices,...
Learn how human-in-the-loop AI works, what makes human oversight meaningful, how to design HITL workflows, and what the current EU...
OpenAI published 722 AI-generated math manuscripts across 372 result families. See what is verified, what Lean checks, and why AI...