AI · Legal
Who pressed the shutter?
Copyright and usage rights in AI image production — three questions that constantly get confused, and why the boundary is never about the process.
Who owns an AI image? The question sounds simple, but it's actually three questions that constantly get confused — and anyone who conflates them gets no useful answer to any of them.
The first: Am I the author at all? Do I have exclusive rights to this image, with which I can prevent others from reusing it? The second: Am I even allowed to use and commercially exploit the image? That's decided not by copyright law but by the license of the model I used to generate it. And the third, actually the most important in commissioned work: What copyright usage rights can I grant my client — time-limited, territory-limited, exclusive or not?
This last term needs a brief clarification, because the word "usage right" means two different things. The model license is a permission between you and the model provider — it says whether you may use the output commercially, and governs only that bilateral relationship. Copyright usage rights, on the other hand, are something different: the rights you as the author carve out of your own copyright and grant to your client — and which operate against the whole world. The first you have (or don't have) vis-à-vis the provider. The second you can only pass on if you are an author in the first place. That's why everything ultimately depends on the first question. And the three questions are independent of each other: you can be entitled to exploit an image in which you hold no copyright — and vice versa.
The thread running through everything: the boundary is never at the process — "AI yes or no?" is the wrong question — but at the human control over the image.
An image to make the starting point concrete. Someone who commissions a photographer and describes the subject precisely in their brief is not the author of the photograph — the shutter belongs to the person behind the camera. With "prompt in, image out," the division of roles is the same: the model is the photographer, the user the client. And from describing the image subject alone, no authorship follows.
Do I own it? It depends on control
The prevailing position (notably the US Copyright Office) holds that purely prompt-based images are not protectable — the human does not determine through the prompt how the image is executed.
Caveat: That is US law; in Germany the relevant framework is the Urheberrechtsgesetz (UrhG), and there it's worth distinguishing two provisions briefly. § 2 protects the work — a personal intellectual creation with a certain level of creative originality. That is the full protection: seventy years beyond the author's death, with all exploitation and usage rights. § 72, by contrast, is only the weaker fallback right for simple photographs — photos that don't reach the threshold of originality, such as a product scan or an evidentiary snapshot. It offers shorter protection and is tied to the photographic process. The key point for us: a controlled Blender rendering is a work under § 2, with everything that entails. It arises from creative decision-making and requires no recording process — a painting has none either and is unquestionably protected. The rendering doesn't need the weaker § 72 at all. The principle is the same across both legal systems: protection follows from creative decision, not from pressing a trigger — whether mechanical or via prompt.
With the controlled workflow, this shifts fundamentally. Anyone who first builds the scene in Blender makes the how themselves, before the model: camera, perspective, framing, light, composition. ControlNet forces the model to follow this geometry; it retains only material and surface. And this isn't a lucky accident, but the oldest justification for image protection: photography became protectable precisely because the photographer makes creative decisions — pose, light, framing. The workflow relocates exactly these decisions into 3D space.
There's also a practical advantage that only this approach provides: Provability. The Blender scene exists as its own, independently protectable file. The Canny map documents the control. In a dispute you present a visible production chain, rather than claiming "I prompted creatively." The right question is therefore not "is my AI image protected?" but "how much of my image decisions can I demonstrate?"
How far does it go? Three levels
What matters is not the visual similarity to the rendering, but how much of the expression traces back to documented decisions.
- Secure is the foundation: the pure Blender rendering (work under § 2) and the composition, which remains yours even in the finished AI image.
- Open is the overall image when generated surfaces or atmosphere carry the expression — for instance with img2img that turns a summer rendering into a November scene: the composition stays, but color, textures, and mood are model-generated. Here: rendering and composition remain yours, the generated element is the unresolved question.
- Public domain is the pure prompt image without human image control.
The core statement stands, and it's simpler than the debate suggests. A pure Blender rendering is a full work with everything that entails. A pure "prompt in, image out" is not protectable. And everything in between is a case-by-case matter in a dispute — a field where clear rulings are still rare, and where the amount of human creative input must be established individually. That's precisely why the most important thing you have in your own hands is a demonstrable, controlled image creation process. In case of doubt, it's your evidence that no random machine image is involved, but a deliberately composed, precisely executed image — one to which § 2 applies.
Three perspectives — who is actually the author?
Before getting to training, an orientation helps, because the whole debate reduces to three possible answers.
- The user — they determine what the image looks like, and are therefore the author. Strong with the controlled workflow, weak with a pure prompt.
- The model — the user only briefs, the model creates. This view underlies the classification of pure prompt images as non-protectable; taken to its conclusion, it means nobody is the author, because a model is not a person and cannot be an author — the image is public domain.
- The training data contributors — everyone whose images went into the training are co-authors. This third view is the weakest, and the next section explains why.
Training is a different question from authorship
The most important thought for untangling the debate: whether the training of a model was permissible, and whether I am the author of the image produced with it, are two entirely separate questions. The first is open and contested — governed in the EU by the so-called text and data mining exception, together with an opt-out right for rights holders; the legislator has therefore explicitly not equated training with human learning, but treated it as a separate process that can be objected to. The second question — am I the author? — depends solely on my image control, not on the training.
Both are independent: you can lawfully own an image whose model was trained on questionable grounds, and vice versa. And from that follows the sentence that disposes of the third perspective above: even unlawful training does not make the training data contributors co-authors of your image. Their contribution is distributed and mixed in the model in a way that can no longer be attributed to any individual — unlawful training is a permissibility problem of the training itself, not a copyright claim on your result.
Your own LoRA: more control, more responsibility
Anyone who trains their own LoRA to achieve a particular look makes a significant creative decision — curating, selecting, and weighting the material is a further layer of human control and strengthens the authorship position. At the same time, the origin of the training material moves to the fore. The problem is not the targeted style — a style is generally not protected, imitating a look is permitted. The problem is the path to it: "photographing in the style of X" is permitted, "training a model directly on X's protected images" is not.
Where a particular project falls between these poles can be assessed with four questions:
- How much own material is in it, how much from others?
- Is the outside material anonymously scraped from the web, or the identifiable work of a named author?
- Under what license does it stand — public domain, Creative Commons, purchased, or scraped?
- How large is the distance of the result from the source material — a merely diffusely absorbed look, or the recognizable reproduction of specific compositions?
The more original, clearly licensed material and the greater the distance, the stronger the position. The most practical consequence for any experienced photographer: your own archive, grown over years, is legally speaking the safest training dataset there is.
Am I allowed to? The model license first
Whether you may work commercially is decided not by copyright law but by the model's license. Broadly there are two families: permissive licenses (e.g. Apache 2.0 — commercial use free without further conditions) and non-commercial licenses (no commercial exploitation of outputs). Non-commercial doesn't mean worthless: for learning, education, and experimentation it's the perfectly legitimate normal case, where no commercial result is being produced anyway. "Only permissive models" is therefore not a workable rule — it would deprive the learner of their best tool. What counts is: the end user bears license responsibility for the model they deploy, and must know which family they're in.
And what can I give my client?
That's the third question, and this is where the first pays off — because this level depends entirely on whether I am the author. As the author (controlled workflow) I grant usage rights like any photographer: simple or exclusive, limited by time, territory, and medium — one year, DACH region, print only, this one campaign only. Further licensing by the client is not automatic; without a contrary agreement it requires my consent, and in case of doubt the client receives only the rights strictly required by the contractual purpose.
With the pure prompt image, this entire toolkit collapses: the image is public domain, I can neither hold nor promise exclusivity, and a third party may also use it — my client included, for that matter. For advertising, which almost always requires exclusivity, this is the practical knockout of the pure prompt image. And AI disclosure doesn't entitle any third party to anything: it says "AI-generated," not "public domain" — anyone who copies a workflow image violates a copyright despite the label, because you can't tell from the image whether a protected creative process lies behind it.
For the studio, this means two things
First: make image control demonstrable. The scene, the map, the traceable editing process are not a byproduct — they are the legal position, and they also determine whether you can give your client exclusivity. Second: know the license situation of your own tools before an image goes to the client. This isn't legal certainty — it's the ability to ask the right questions before someone else asks them.
Note
A reasoned position, not legal advice. The legal situation referenced was researched in early August 2026; US decisions are illustrative, not binding in Germany. No definitive answers exist for individual cases yet — consult a lawyer specializing in copyright law in case of doubt.