Uploading an Image Used to Be a Neutral Act.
Two Regulators Just
Made It a Declaration.
Washington now asks what a human contributed. Brussels
asks whether the rightsholder said no. Neither question existed when image
hosting was invented.
For most of the internet's history, putting a picture on a
server raised exactly one legal question: did you have the right to put it
there. Everything else — how the image was made, what tools touched it, whether
anyone could claim it afterwards — sat outside the frame.
That changed twice in the space of about eighteen months, in
two jurisdictions, for unrelated reasons.
Washington: the machine's share has to be
declared
The United States Copyright Office restated its position in
Part 2 of its report on copyright and artificial intelligence, and the
restatement is narrower and more demanding than the summaries of it suggest.
Human authorship remains an essential requirement for
copyright protection in the United States. That much is old law. The operative
addition is procedural: if a work contains more than a de minimis amount of
AI-generated material, the applicant must disclose that and provide a brief statement
describing the human author's contribution.
So registration now includes an accounting question. Not
"is this yours" but "which parts of this are yours, and say so
in writing."
The report works through three kinds of human contribution
to AI-generated output: prompts that instruct a system to generate something,
expressive inputs that can be perceived in the result, and modifications or
arrangements of what the system produced. Worth noting because the count gets
misreported: three, not four.
And the Office is blunt about the first of them. On the
functioning of current generally available technology, prompts alone do not
establish authorship of the output. Most commenters agreed that entering simple
prompts is insufficient to make the user an author — prompts were widely
described as unprotectible ideas rather than expression. The Office allows that
a sufficiently creative prompt might itself be copyrightable as a text, which
is a different claim from owning the image it produced.
The underlying standard is not new. The Compendium of
Copyright Office Practices has carried a section headed "The Human
Authorship Requirement" for years — §306 of Chapter 300, in an edition dated
January 2021, well before any of this was topical.
Brussels: the rightsholder's "no" has
to be honoured
The European approach starts from the opposite end. It says
nothing about who owns the output and everything about what went into the
model.
Under Regulation (EU) 2024/1689, providers of
general-purpose AI models must put in place a policy to comply with Union
copyright law, and specifically must identify and comply with — "including through
state-of-the-art technologies" — a reservation of rights
expressed under Article 4(3) of Directive (EU) 2019/790.
That reservation is the opt-out. Text and data mining over
protected works is permitted under the earlier directive, but rightsholders may
reserve their rights to prevent it, and where they have done so in an
appropriate manner, a model provider needs actual authorisation to mine those
works.
Two details give the obligation unusual reach.
First, it applies regardless of where the training happened.
The Regulation states the duty binds any provider placing a model on the Union
market, whatever jurisdiction the copyright-relevant acts took place in —
reasoning that no provider should gain a competitive advantage in the Union by
applying lower copyright standards.
Second, open-source models get relief from some transparency
requirements but not from this one. The exemption, the text says, does not
extend to the obligation to produce a summary of training content or to
maintain a copyright compliance policy.
What this does to a gallery
Put the two together from the position of somebody who hosts
images rather than makes them.
An American user who wants an enforceable claim over a
picture now has to be able to say what they personally contributed. A European
model builder who wants to train on that picture has to check whether its owner
attached a machine-readable refusal. Both requirements attach to metadata and
provenance — to information about the image rather than the image itself.
Image hosting was never designed to carry that information.
A gallery stores files, serves thumbnails and counts views. It has no field for
"which parts of this are human," and no reliable way to propagate an
opt-out signal that a later crawler will respect.
The practical result is a gap between what the law now
assumes exists and what the infrastructure actually records.
Where the same gap shows up in finding people
The identical problem appears one layer over, in a place
nobody legislated about.
Subscription platforms hold images and pages belonging to
individuals, and they store almost nothing that would let a stranger locate a
particular person by anything other than an exact handle. There is no field for
what someone publishes, no structure that makes the catalogue traversable. The
consequence is that discovery migrates outward: services such as SpicyCreator
read what is publicly stated on profiles and sort it into categories a person
can actually browse.
The honest boundary on that is the same boundary the
regulators keep running into. Such a service records assertions, not verified
facts; it reflects the state of a profile at the moment it was read; and it
cannot represent anyone who published nothing publicly. Provenance is exactly
what is missing, in the small case and the large one.
What these documents do and do not settle
The Copyright Office report is guidance on how the Office
will examine applications. It is not a statute, and courts remain free to read
the Copyright Act differently — several of the cases the report cites are still
working their way through litigation.
The Regulation is binding law with a phased application
timetable, and the copyright obligations sit within a broader compliance regime
whose enforcement practice does not exist yet. What "state-of-the-art
technologies" means for detecting a reservation of rights is not defined
in the text.
Neither instrument addresses the case that is most common on
a gallery: an ordinary photograph, taken by a person, uploaded by someone else
entirely. That question is as old as image hosting and neither regulator
touched it.
What both did do is add a question to an act that used to
have none. Uploading a file now implies a claim about where it came from — and
the systems doing the storing were built when nobody was asking.
|