IP in agent output: autonomy weakens your ownership and your indemnity at the same time.
"Who owns what the agent produced?" is two questions wearing one sentence, and the answers move in the same direction for the same reason. Your ability to stop others copying the output depends on a human having made creative choices; your vendor's promise to defend you if the output infringes depends on conditions an autonomous agent routinely breaks. Both degrade as you remove the human — so the one control that pays twice is a record of which human decisions shaped which artifact. This page is operational guidance, not legal advice; get counsel for your jurisdiction.
Separate the two questions before anyone answers either.
Most internal debates about AI and IP are two conversations colliding, and they have different owners, different evidence and different remedies.
- The offensive question — can you stop others copying it? This is copyright subsistence and ownership. It matters when the output is the product: marketing copy, product documentation, generated code you licence, designs, training material, anything you would send a takedown about.
- The defensive question — can others stop you? This is infringement exposure. It matters for every output, including internal ones, and it is the question that produces lawsuits rather than lost revenue.
- They have opposite risk profiles. Losing the offensive question costs you an asset you thought you had. Losing the defensive question costs you a legal proceeding. Teams that discuss only ownership are optimising the cheaper failure.
- Only one of them is contractual. Ownership is decided by law and by facts about how the work was made; your vendor cannot grant it to you no matter what the terms say. Exposure, by contrast, is substantially allocated by contract — which is why the terms are worth reading closely and the ownership clause is worth reading sceptically.
Note what a vendor's "you own the output" clause actually does. It is the provider waiving any claim they might have — a useful and real thing. It is not, and cannot be, a statement that copyright subsists in the output at all. If nothing is owned, the clause transfers nothing, and the sentence remains literally true.
Ownership: three jurisdictions, three rules, one shared requirement.
The rules genuinely differ by country, which matters if you operate across them — but they converge on what they want to see.
- United States — human authorship required, assessed case by case. The Copyright Office has held consistently, in its 2023 registration guidance and its January 2025 report, that copyright protects only material that is the product of human creativity, and the courts have applied the same rule to AI output. A prompt alone, however detailed, does not make you an author. Human selection, arrangement and editing of AI output can support protection — for those contributions, not for the raw generation.
- United Kingdom — a statutory exception that may not survive. Section 9(3) of the Copyright, Designs and Patents Act 1988 assigns authorship of a computer-generated work with no human author to "the person by whom the arrangements necessary for the creation of the work are undertaken", with 50 years of protection. The government's Report on Copyright and AI, published 18 March 2026, found most respondents favoured removing it while retaining protection for AI-assisted works. Reform is paused, not settled; do not build a business on a provision under active review.
- China — protection granted, on evidence of creative effort. In November 2023 the Beijing Internet Court decided Li v. Liu, finding a Stable Diffusion image copyrightable because the process reflected the plaintiff's aesthetic choices and personal judgement from conception through final selection. Subsequent Beijing Internet Court decisions have made the corollary explicit: a claimant must produce evidence of that creative effort, not merely assert it.
Different doctrines, one operational consequence. Every route to protection runs through a human's creative choices, and in the jurisdiction most willing to grant protection, those choices must be evidenced. That is not a legal problem. It is a logging problem, and you already own the logs.
Indemnity: read the conditions, not the headline.
The major providers offer some form of IP indemnity — Microsoft's Copilot Copyright Commitment from September 2023, OpenAI's Copyright Shield from November 2023, Anthropic's commitment in its commercial terms, Google's for Workspace AI features. Coverage is real. The conditions are where agent deployments fall out.
- Plan and product scope. Indemnities generally attach to enterprise or commercial tiers and to named services. An agent calling a consumer tier, a free tier, or a model reached through an aggregator may sit outside the covered surface entirely.
- Safety systems must remain enabled. Coverage is typically conditioned on using the provider's filters and mitigations unmodified. Any team that disabled a filter because it interfered with a tool loop should check whether it also disabled the indemnity.
- You must not have supplied infringing input. This is the condition agents break by construction. An agent that retrieves web pages, ingests customer documents, or pulls from a corpus nobody cleared is supplying inputs on its own initiative, and the provenance of those inputs is now your responsibility to establish.
- You must not have known. Most terms exclude claims where the customer had reason to believe the output would infringe. An agent generating at scale, unreviewed, makes "reason to believe" a question about your monitoring rather than about any individual output.
- Prompting for it voids it. Requests that target a specific protected work — "in the style of", a named character, a competitor's copy — are typically excluded. In an agent, that prompt may come from a user, a retrieved document, or another agent, and you are the one who has to prevent it.
- Chains have no indemnity. A supervisor calling a sub-agent on a different provider through a third-party framework has an obligation chain no single indemnity spans. Map it the way you would any other dependency, per third-party model and vendor risk.
Autonomy is the axis both slide down.
Here is the part that does not appear in either the legal memo or the architecture review, because it only shows up when you put them side by side.
- The same variable governs both. Human involvement is what earns protection on the offensive side and what preserves the "we neither supplied nor knew" position on the defensive side. Raising autonomy spends both at once, and neither cost appears in the business case for raising it.
- Volume converts a per-output risk into a systemic one. One unreviewed page is a small exposure. Forty thousand of them is a pattern, and a pattern is what makes "should have known" arguable.
- Retrieval moves the risk upstream of the model. When an agent grounds its output in documents it fetched itself, the infringement question is partly about your corpus, not the provider's training data — and no model-provider indemnity was ever going to cover what your agent went and got.
- Agent-to-agent output compounds it. Output from one agent becomes input to the next. By the third hop nobody can say what the artifact was derived from, which is precisely the record both questions demand.
- So price it into the autonomy decision. Where output is a commercial asset or ships to customers, "how much human judgement is in this artifact?" is an IP control, not a quality preference. The ladder in autonomy levels has an IP column nobody drew.
The controls, in the order they pay off.
Four of these are engineering work you can start this quarter. The fifth is a conversation with your vendor.
- Record the human decisions, not just the tokens. Which options a person was shown, which they chose, what they rewrote, what they rejected, who they were and when. This single artifact is your evidence of creative effort in a jurisdiction that demands it, your evidence of review where "should have known" is at issue, and your provenance trail when someone asks where a paragraph came from. It is the record described in decision receipts, kept for a different purpose.
- Know your corpus. Licence status of every source an agent may retrieve from and every document it may ingest. Scraped web content, competitor material and customer-supplied files each carry different terms, and "the agent found it" is not a provenance answer. This is a data governance obligation that agentic retrieval quietly widened.
- Check outputs where the stakes justify it. Similarity screening against known corpora for anything published at scale; licence detection for generated code that will be distributed. Not every output needs this — high-volume, externally-published, or redistributed artifacts do.
- Mark the artifacts. Carry the generation record with the work, not in a separate system, so a question three years from now has an answer. The mechanics are the same as in disclosure and content provenance, and the two obligations are cheaper built together than separately.
- Ask your vendor four questions in writing. Does the indemnity cover this SKU and this model? Does it survive our retrieval-augmented use? What must remain enabled? What is the cap? Vendor answers vary more than the marketing pages suggest, and the answer you get in writing is the one your counsel can rely on.
Decide what is an asset, and treat only that differently.
The failure mode of an IP policy is uniformity: applied everywhere it stops the agent being useful, applied nowhere it fails on the one output that mattered. Sort by what the artifact is for.
- Internal and disposable — summaries, drafts, analyses nobody publishes. Exposure risk only, and low. Do not spend review here; you will need that attention elsewhere.
- Published at volume — support articles, product copy, generated documentation. Exposure risk is the live one, because scale is what makes a pattern. Screening and monitoring, light human review.
- Commercial assets — anything you would licence, enforce, or sell. Both questions bind. This is where a documented human creative contribution is worth the cost of collecting it, and where an unreviewed generative pipeline is quietly manufacturing unprotectable inventory.
- Distributed code — its own category, because licence contamination is a distinct mechanism with distinct tooling and it travels into your customers' products.
- Say it in the accountability map. Who owns the answer to each question, per artifact class, alongside the other role assignments in accountability and roles. In most organisations today, nobody owns this one.
Start by listing which of your agent's outputs you would ever want to enforce a right in. For most teams the list is short — and everything on it needs a documented human creative contribution, captured at the moment it happens, because no jurisdiction will let you reconstruct it afterwards. For everything else, the useful work is upstream: know what your agent is allowed to retrieve, and get your vendor's indemnity conditions in writing before you find out which one you broke. Ownership and indemnity are not two topics — they are the same variable read from opposite ends, and that variable is how much of a human is still in the artifact.
Related: the regulatory landscape for how these obligations sit beside the statutory ones, audit trails for the record-keeping mechanism, policy enforcement for putting the retrieval rules in the loop rather than in a document, and data residency and sovereignty for the other axis on which jurisdiction changes your answer.